> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure EAP Extensible Authentication Protocol Types

> Configure EAP authentication types for 802.1X on Apple devices using Iru Endpoint. Set up TLS, TTLS, PEAP, and EAP-FAST for Wi-Fi and Ethernet profiles.

<Callout icon="apple" color="#B84A7A" iconType="regular">This guide applies to Mac computers</Callout>

Numerous options are available for authenticating to Wi-Fi or wired networks, especially if your infrastructure supports more than one authentication type. Each option has unique settings you need to configure. This article covers the most common configuration options. For more information about configuring enterprise networks, see our [Configure the Wi-Fi Library Item](/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item) and [Configure the Ethernet Library Item](/en/endpoint/library/library-items-profiles/configure-the-ethernet-library-item) support articles.

<Warning>
  Your network infrastructure must support the chosen EAP types and be configured correctly to allow authentication. If you do not know how your network is configured, work with your network administrators to determine how they want network clients to connect.
</Warning>

### Configure EAP-TLS

EAP-TLS uses Transport Layer Security and an identity certificate to authenticate devices to the network.

<Warning>
  You must provide an identity certificate to use EAP-TLS.
</Warning>

<Steps>
  <Step title="Select EAP Type">
    Select TLS under **Accepted EAP Types**.
  </Step>

  <Step title="Set TLS minimum version">
    To prevent using older and weaker TLS versions, select the **TLS minimum version** you would like to allow.
  </Step>

  <Step title="Set TLS maximum version">
    If your infrastructure does not support the latest versions of TLS, select the **TLS maximum version** you want to use.
  </Step>

  <Step title="Configure Identity Certificate">
    Select a method to provide an identity certificate and configure applicable settings. See [Configure the Wi-Fi Library Item](/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item) to learn more.

    <Frame>
      <img src="https://mintcdn.com/iru/31OfB-o1LvAjxToj/assets/media/images/7olbns6l7hhiv3jx5lblk-_ypsy3uat3jw.png?fit=max&auto=format&n=31OfB-o1LvAjxToj&q=85&s=b6342a20c87fe78d159e66ba9c337bac" alt="Wi-Fi Library Item Identity certificate and EAP configuration" width="2940" height="3834" data-path="assets/media/images/7olbns6l7hhiv3jx5lblk-_ypsy3uat3jw.png" />
    </Frame>
  </Step>
</Steps>

### Configure EAP-TTLS

Tunneled Transport Layer Security uses a TLS tunnel to encrypt another authentication protocol. It does not require an identity certificate.

Devices can use a username and password or device-based directory credentials to authenticate.

Username and password authentication:

<Steps>
  <Step title="Select Authentication Method">
    Choose **Username and password** for **Authentication**.
  </Step>

  <Step title="Configure Username">
    Optionally, provide the **Username**. You can use a static value or one of [Iru Endpoint's global variables](/en/endpoint/library/library-items-profiles/global-variables), such as \$EMAIL. If you do not enter a username, the device prompts the user to enter one when connecting to the network.
  </Step>

  <Step title="Set Password Prompt Frequency">
    Select how often to prompt the user for their password. If you choose **Once** and don't provide a password, the device will prompt the user once for their password and remember it. If you select, **Every time the user connects to the network**, the device will not remember the password.
  </Step>

  <Step title="Configure Password">
    If devices use a shared username and password, enter the password in the **Password** field. If you do not enter a password, the device prompts the user to enter a password when connecting to the network.

    <Frame>
      <img src="https://mintcdn.com/iru/TTV4GXkIHgRpdDZ5/assets/media/images/vX5UJ5ANxbGeQtB41cioXIC0wmv3_mEgmQ(1).png?fit=max&auto=format&n=TTV4GXkIHgRpdDZ5&q=85&s=67480d44c947ee458a01e5d3926ca780" alt="EAP configuration showing certificate or network authentication settings" width="3080" height="3010" data-path="assets/media/images/vX5UJ5ANxbGeQtB41cioXIC0wmv3_mEgmQ(1).png" />
    </Frame>
  </Step>
</Steps>

Device-based directory authentication for a Mac bound to a directory service:

<Steps>
  <Step title="Choose authentication method">
    Choose either **Computer AD system authentication** to use the Active Directory computer account or **Computer OD system authentication** to use the Open Directory computer account.
  </Step>
</Steps>

Configure the remaining TTLS settings:

<Steps>
  <Step title="Configure TTLS authentication">
    When you select TTLS, your device will use a username and password or device directory credentials for authentication. If your network requires an identity certificate as a second authentication factor, select **Require Two-Factor Authentication.**
  </Step>

  <Step title="Set inner authentication">
    For **Inner authentication**, choose the authentication protocol to use inside the TLS tunnel.
  </Step>

  <Step title="Specify outer identity (optional)">
    Optionally specify **Outer identity.** It is different from the identity used inside the tunnel and is specified to prevent exposing the inner identity.
  </Step>

  <Step title="Set TLS minimum version">
    To prevent using older and weaker TLS versions, select the **TLS minimum version** you would like to allow.
  </Step>

  <Step title="Set TLS maximum version">
    If your infrastructure does not support the latest versions of TLS, select the **TLS maximum version** you want to use.
  </Step>
</Steps>

### Configure EAP-LEAP

Lightweight Extensible Authentication Protocol is an older authentication method based on MS-CHAP and Dynamic WEP. It does not use an identity certificate.

Devices can use a username and password or device-based directory credentials to authenticate.

Username and password authentication:

<Steps>
  <Step title="Choose authentication method">
    Choose **Username and password** for **Authentication**.
  </Step>

  <Step title="Configure username (optional)">
    Optionally, provide the **Username**. You can use a static value or one of [Iru Endpoint's global variables](/en/endpoint/library/library-items-profiles/global-variables), such as \$EMAIL. If you do not enter a username, the device prompts the user to enter one when connecting to the network.
  </Step>

  <Step title="Set password prompt frequency">
    Select how often to prompt the user for their password. If you choose **Once** and don't provide a password, the device will prompt the user once for their password and remember it. If you select **Every time the user connects to the network**, the device will not remember the password.
  </Step>

  <Step title="Configure password (optional)">
    If devices use a shared username and password, enter the password in the **Password** field. If you do not enter a password, the device prompts the user to enter a password when connecting to the network.

    <Frame>
      <img src="https://mintcdn.com/iru/eqrMRa098FywfIL4/assets/media/images/sitfamfjwirkrhegit6m_fpsb9lpbgexqg.png?fit=max&auto=format&n=eqrMRa098FywfIL4&q=85&s=013de1461baebb88342e8e561580cd23" alt="EAP password field for shared username and password" width="3026" height="2756" data-path="assets/media/images/sitfamfjwirkrhegit6m_fpsb9lpbgexqg.png" />
    </Frame>
  </Step>
</Steps>

Device-based directory authentication for a Mac bound to a directory service:

<Steps>
  <Step title="Choose directory authentication">
    For **Authentication,** choose **Computer AD system authentication** to use the Active Directory computer account or **Computer OD system authentication** to use the Open Directory computer account.
  </Step>
</Steps>

### Configure EAP-PEAP

Protected Extensible Authentication Protocol addresses shortcomings of previous Extensible Authentication Protocols such as LEAP. Like EAP-TTLS, PEAP uses a TLS tunnel to encrypt another authentication protocol. It does not require an identity certificate.

Devices can use a username and password or device-based directory credentials to authenticate.

Username and password authentication:

<Steps>
  <Step title="Choose authentication method">
    Choose **Username and password** for **Authentication**.
  </Step>

  <Step title="Configure username (optional)">
    Optionally, provide the **Username**. You can use a static value or one of [Iru Endpoint's global variables](/en/endpoint/library/library-items-profiles/global-variables). For example, \$EMAIL. If you do not enter a username, the device prompts the user to enter one when connecting to the network.
  </Step>

  <Step title="Set password prompt frequency">
    Select how often to prompt the user for their password. If you choose **Once** and don't provide a password, the device will prompt the user once for their password and remember it. If you select, **Every time the user connects to the network**, the device will not remember the password.
  </Step>

  <Step title="Configure password (optional)">
    If devices use a shared username and password, enter the password in the **Password** field. If you do not enter a password, the device prompts the user to enter a password when connecting to the network.
  </Step>
</Steps>

Device-based directory authentication for a Mac bound to a directory service:

<Steps>
  <Step title="Choose directory authentication">
    For **Authentication,** choose **Computer AD system authentication** to use the Active Directory computer account or **Computer OD system authentication** to use the Open Directory computer account.
  </Step>
</Steps>

Configure the remaining PEAP settings:

<Steps>
  <Step title="Configure PEAP authentication">
    When you select PEAP, your device will use a username and password or device directory credentials for authentication. If your network requires an identity certificate as a second authentication factor, select **Require Two-Factor Authentication.**
  </Step>

  <Step title="Set TLS minimum version">
    To prevent using older and weaker TLS versions, select the **TLS minimum version** you would like to allow.
  </Step>

  <Step title="Set TLS maximum version">
    If your infrastructure does not support the latest versions of TLS, select the **TLS maximum version** you want to use.
  </Step>

  <Step title="Specify outer identity (optional)">
    Optionally, specify **Outer identity.** It is different from the identity used inside the tunnel and is specified to prevent exposing the inner identity.
  </Step>
</Steps>

### Configure EAP-FAST

Flexible Authentication via Secure Tunneling (FAST) uses a TLS tunnel to encrypt additional authentication information. FAST also supports fast re-establishment of the tunnel through Protected Access Credentials (PAC). It does not require an identity certificate.

A username and password or device-based directory credentials can provide authentication.

Username and password authentication:

<Steps>
  <Step title="Choose authentication method">
    Choose **Username and password** for **Authentication**.
  </Step>

  <Step title="Configure username (optional)">
    Optionally, provide the **Username**. You can use a static value or one of [Iru Endpoint's global variables](/en/endpoint/library/library-items-profiles/global-variables). For example, \$EMAIL. If you do not enter a username, the device prompts the user to enter one when connecting to the network.
  </Step>

  <Step title="Set password prompt frequency">
    Select how often to prompt the user for their password. If you choose **Once** and don't provide a password, the device will prompt the user once for their password and remember it. If you select, **Every time the user connects to the network**, the device will not remember the password.
  </Step>

  <Step title="Configure password (optional)">
    If devices use a shared username and password, enter the password in the **Password** field. If you do not enter a password, the device prompts the user to enter a password when connecting to the network.
  </Step>
</Steps>

Device-based directory authentication for a Mac bound to a directory service:

<Steps>
  <Step title="Choose directory authentication">
    For **Authentication,** choose **Computer AD system authentication** to use the Active Directory computer account or **Computer OD system authentication** to use the Open Directory computer account.
  </Step>
</Steps>

Configure the remaining EAP-FAST settings:

<Steps>
  <Step title="Configure EAP-FAST authentication">
    When you select EAP-FAST, your device will use a username and password or device directory credentials for authentication. If your network requires an identity certificate as a second authentication factor, select **Require Two-Factor Authentication.**
  </Step>

  <Step title="Specify outer identity (optional)">
    Optionally specify **Outer identity.** It is different from the identity used inside the tunnel and is specified to prevent exposing the inner identity.
  </Step>

  <Step title="Enable PAC usage">
    To use Protected Access Credentials, select **Use PAC**.
  </Step>

  <Step title="Enable PAC provisioning">
    To use Protected Access Credentials, select **Provision PAC**.
  </Step>

  <Step title="Enable anonymous PAC provisioning">
    If you would like to provision the PAC anonymously, select **Provision PAC anonymously**.
  </Step>
</Steps>

### Configure EAP-SIM

<Note>
  This authentication method is compatible with the [Wi-Fi Library Item](/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item) only.
</Note>

EAP-SIM uses a device’s Subscriber Identity Module (SIM) for a Global System for Mobile Communications (GSM) network to authenticate to Wi-Fi. This EAP type is used in very few environments —for example, if you are a Mobile Network Operator (MNO) or a Mobile Virtual Network Operator (MVNO). It does not require an identity certificate.

<Steps>
  <Step title="Configure RAND values">
    Choose the **Minimum number of RAND** **values** the devices requires from the server. The available options are **3** (default), **2**, or **Don't specify**. More RAND challenges result in stronger keying material.

    <Frame>
      <img src="https://mintcdn.com/iru/1OVymKHk38EquoaD/assets/media/images/wyxNZgiEEOesaLoi9cOkmJZumN-wj_fe5g.png?fit=max&auto=format&n=1OVymKHk38EquoaD&q=85&s=105e1f8ea09ae1f18694e6422e3841a1" alt="EAP Minimum number of RAND values option" width="2996" height="814" data-path="assets/media/images/wyxNZgiEEOesaLoi9cOkmJZumN-wj_fe5g.png" />
    </Frame>
  </Step>
</Steps>

### Configure EAP-AKA

<Note>
  This authentication method is compatible with the [Wi-Fi Library Item](/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item) only.
</Note>

EAP-AKA (Authentication and Key Agreement) uses a device’s identity module for a Universal Mobile Telecommunications System (UMTS) and CDMA2000 network to authenticate to Wi-Fi. This EAP type is used in very few environments —for example, if you are a Mobile Network Operator (MNO) or a Mobile Virtual Network Operator (MVNO). It does not require an identity certificate. There are no options to configure for this EAP type.

<Frame>
  <img src="https://mintcdn.com/iru/1OVymKHk38EquoaD/assets/media/images/xa2vviy8p1jthq6xf7xcuar7ixbsupdxtq.png?fit=max&auto=format&n=1OVymKHk38EquoaD&q=85&s=188c321a085bb198e57d2a1ee2cda80d" alt="EAP-AKA option for UMTS or CDMA2000 network authentication" width="2994" height="552" data-path="assets/media/images/xa2vviy8p1jthq6xf7xcuar7ixbsupdxtq.png" />
</Frame>

### Related Articles

<CardGroup cols={2}>
  <Card title="Network Authentication Overview" icon="wifi" href="/en/endpoint/networking-and-connectivity/network-authentication-overview">
    Compare Wi-Fi authentication types and when to use enterprise vs non-enterprise options
  </Card>

  <Card title="Configure the Wi-Fi Library Item" icon="wifi" href="/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item">
    Configure the Wi-Fi Library Item for network deployment
  </Card>

  <Card title="Configure the Ethernet Library Item" icon="network-wired" href="/en/endpoint/library/library-items-profiles/configure-the-ethernet-library-item">
    Configure 802.1X authentication for wired networks
  </Card>

  <Card title="Using Identity Certificates for 802.1X Authentication" icon="certificate" href="/en/endpoint/integrations/certificate-services/using-identity-certificates-for-802-1x-authentication">
    Use identity certificates for 802.1X authentication
  </Card>
</CardGroup>
