dot1x failed

Handian Sudianto 7,511 Reputation points
2026-10-08T04:01:39.2+00:00

Sometime we facing issue the client suddently disconnect from the network and i got below error.

Is the client send different certificate to the nac? This is not permanent issue because if i re-plug the cable then the client can connect again

User's image

Windows for business | Windows Client for IT Pros | Networking | Network connectivity and file sharing
0 comments No comments

2 answers

Sort by: Most helpful
  1. Harry Phan 34,045 Reputation points Independent Advisor
    2026-10-08T04:11:34.3+00:00

    Hello Handian,

    No, this does not necessarily mean the client is sending a different certificate. Error 0x80420105 indicates that the certificate presented during 802.1X authentication was rejected by the NAC/RADIUS server.

    Since re-plugging the cable restores connectivity, this is more likely an intermittent reauthentication or certificate-selection issue than a permanently invalid certificate. Check the NAC/RADIUS logs at the failure timestamp and compare the certificate thumbprint/serial number with the successful authentication after re-plugging. Also check Event Viewer > Microsoft > Windows > Wired-AutoConfig > Operational on the client; if the same certificate fails first and succeeds after re-plugging, focus on the 802.1X reauthentication/session handling rather than certificate replacement.

    Harry P.

    Was this answer helpful?


  2. AI answer

    2026-10-08T04:02:00.94+00:00

    Yes. The error indicates that certificate-based 802.1X authentication was attempted, and the certificate presented for user authentication was rejected by the server.

    From the message shown:

    • Reason Text: "The authentication failed because the user certificate required for this network was rejected by the server"
    • Identity: host/...

    That points to a certificate validation problem during EAP authentication, not a random disconnect by itself. Common certificate-related causes in this scenario include:

    • expired certificate
    • invalid certificate
    • certificate chain verification failure
    • certificate revocation check failure
    • wrong or missing extended key usage (EKU)
    • multiple matching certificates on the device, causing the wrong certificate to be selected

    For Windows 802.1X, these are the most useful checks:

    1. Check the wired 802.1X client log
    • Open Event Viewer
    • Go to Applications and Services Logs > Microsoft > Windows > Wired-AutoConfig > Operational
    • Review the failure event at the disconnect time
    1. Check certificate validation details
    • In Event Viewer, go to Applications and Services Logs > Microsoft > Windows > CAPI2
    • Right-click Operational and select Enable Log if it is not already enabled
    • Reproduce the issue and review certificate chain, revocation, and trust errors
    1. Verify the certificate on the client
    • Confirm the certificate used for 802.1X is still valid and not expired
    • Confirm the certificate chain is trusted
    • Confirm it has the proper EKU for authentication
    1. Check whether the wrong certificate is being selected
    • If the device has multiple certificates and the wired or Wi-Fi EAP profile does not use strict filtering, Windows can auto-select the wrong certificate and authentication can fail
    • The profile should be configured so it matches only one intended certificate
    1. Verify the server-side EAP configuration
    • On the NPS side, check which certificate is configured for the EAP method
    • In NPS snap-in, go to Policies > Network Policies > [policy] > Properties > Constraints > Authentication Methods
    • Confirm the expected certificate and EAP method are configured

    Relevant 802.1X certificate failure categories documented by Windows include:

    • server certificate expired, invalid, not found, or revoked
    • user certificate expired, invalid, or revoked
    • trusted root certificate expired or invalid

    So the most likely answer is: the client is sending a certificate, but the NAC/NPS is rejecting it. If multiple certificates exist on the endpoint, it can also be sending a different certificate than intended.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.