If everything is okay, don't forget to share your experience with the issue by "Accept answer". If you need more information, feel free to leave a message. We are happy to help!
Enterprise Wi-Fi 802.1X Certificate Trust Warning
Hi guys
Corporate laptops display untrusted certificate warnings when connecting to secure 802.1X SSIDs. What is the recommended way to deploy the required intermediate CA certificates through Group Policy (GPO) so clients trust the RADIUS server certificate?
Thank you for your answer!
Windows for business | Windows Client for IT Pros | Networking | Network connectivity and file sharing
2 answers
Sort by: Most helpful
-
HLBui 13,260 Reputation points Independent Advisor
2026-10-02T06:33:05.9466667+00:00 Hi Pate Adiya
When the client devices do not trust the full certificate chain presented by the RADIUS server. The recommended approach is to deploy the required intermediate CA certificates through Group Policy by importing them into Computer Configuration > Policies > Windows Settings > Security Settings > Public Key Policies > Intermediate Certification Authorities. This ensures all domain-joined devices automatically trust the intermediate CA that issued the RADIUS server certificate.
You'll also want to verify that the root CA certificate is present in the Trusted Root Certification Authorities store, since missing root certificates can cause similar warnings. After the GPO is linked and applied, run gpupdate /force on a test client and confirm the certificates appear in the local computer certificate store. It's also a good idea to validate that the RADIUS server is sending the complete certificate chain during EAP authentication, as an incomplete chain can still trigger trust warnings even when the CA certificates are deployed correctly.
In most environments, deploying both the root and intermediate CA certificates through GPO is the cleanest and most scalable solution for 802.1X wireless authentication. If you find this answer helpful, please go ahead and hit "Accept Answer" so others can benefit from it as well.