Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Hard
A Microsoft 365 Endpoint Administrator needs to configure a custom Wi-Fi profile for corporate-owned iOS devices. The Wi-Fi network uses WPA2 Enterprise with 802.1X authentication and requires users to authenticate with their Azure AD credentials. Which type of Wi-Fi profile should the administrator create in Microsoft Intune?
- AEnterprise Wi-Fi profile (EAP-TLS)
- BPersonal Wi-Fi profile (WPA/WPA2)
- CBasic Wi-Fi profile
- DEnterprise Wi-Fi profile (PEAP)
Show answer & explanationAnswer & explanation
Correct answer: D. Enterprise Wi-Fi profile (PEAP)
For WPA2 Enterprise with 802.1X authentication using Azure AD credentials, PEAP (Protected Extensible Authentication Protocol) is the most common and appropriate EAP type when using username and password (credentials) for authentication. EAP-TLS typically requires client certificates.
Why the other options are wrong
- A. EAP-TLS requires client-side certificates for authentication, not just Azure AD credentials.
- B. Personal Wi-Fi profiles are for WPA/WPA2 networks using a pre-shared key, not enterprise authentication.
- C. A Basic Wi-Fi profile is for simple networks without enterprise-level authentication.
Intune iOS Wi-Fi PEAP Profile
Configuring an Enterprise Wi-Fi profile in Intune for iOS devices that uses PEAP (Protected Extensible Authentication Protocol) for 802.1X authentication with username/password credentials.
- PEAP uses a server certificate for server authentication and then username/password for client authentication.
- Commonly integrated with Active Directory or Azure AD credentials.
- Suitable for WPA2 Enterprise networks requiring credential-based authentication.
Memory trick: PEAP for Passwords, TLS for Certificates.