# Check EAP profile trust after a Windows 11 upgrade

> Why can a formerly working EAP profile fail server validation after an upgrade?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-218-check-eap-profile-trust-after-a-windows-11-upgrade/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:33+00:00
- Modified: 2026-09-08T18:29:33+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Why can a formerly working EAP profile fail server validation after an upgrade?

## Potentially affected

Administrators troubleshooting Windows 11 EAP server-certificate validation for Wi-Fi, Ethernet, or VPN.

## DSE recommendation

Compare an affected pilot profile with its intended root and server-name settings.

## Article

## Source facts

Windows 11 applies a consistent server-certificate validation model across the EAP methods supplied with Windows, including wired, wireless, and VPN use. Microsoft notes that some Windows 10 PEAP or EAP-TLS connections could validate with only a root certificate in the trusted store; upgrade failures therefore warrant checking the connection profile. For the documented upgrade issue, specifying the root certificate thumbprint in the profile is usually sufficient when that root already exists in the trusted store. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/networking/technologies/extensible-authentication-protocol/windows-11-changes).

## Applicability

Confirm that the failure concerns server validation and identify the exact profile used by the upgraded client. Read all applicable trust conditions, including configured server-name validation. Do not infer that a trusted-store entry alone satisfies the Windows 11 profile.

## DSE recommendation

Compare an affected pilot profile with its intended root and server-name settings. Ask the identity and network owners to verify the certificate actually presented by the authentication service. Correct the managed profile only after that identity is established. Preserve server validation rather than disabling it to restore connectivity, and retain the original profile for comparison.

## Verification

Reapply the reviewed profile and repeat the approved connection. Confirm the expected server certificate and profile trust settings, then capture the authentication result. Include a controlled wrong-server or untrusted-certificate case in the test plan so restored connectivity is not the only acceptance condition.

## Official references

[Microsoft Learn: EAP – What’s changed in Windows 11](https://learn.microsoft.com/en-us/windows-server/networking/technologies/extensible-authentication-protocol/windows-11-changes). Source reviewed September 8, 2026.

## Primary reference

- Name: EAP - What's changed in Windows 11
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/technologies/extensible-authentication-protocol/windows-11-changes
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check EAP profile trust after a Windows 11 upgrade,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-218-check-eap-profile-trust-after-a-windows-11-upgrade/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
