Attempting to log in to device using NPS Radius with the protocol "MS-CHAP"

Good morning.

I have currently enabled Radius authentication all the MikroTiks of the network -using Windows Server 2019 NPS and Active Directory groups-. The mentioned setup works as expected when using the protocol “PEAP”. However, I would like to change this so that the “MS-CHAP” protocol is used instead.

In order to apply said change, I have tried eliminating the EAP Type from the Authentication Methods of the Network Directive (please see attached screenshot). To be specific, I remove the line inside the red box.

However, as I apply the change, the authentication to the MikroTik devices does no longer work. Presumably, this is because of the fact that the MikroTik device does not trust the certificate (although I am not completely sure about this).

Is there anything I can do to make it work?

Thank you very much for your attention.

Best regards.
attach1.png

Hello Auxmtik,

I have the same issue. Were you able to resolve this issue? If yes, can you please share what have you done?

Thanks.

Any update? Did you figure out how to accomplish this?