Joining the AD domain is only needed if you need to do MSCHAPv2 authentication against the AD domain. Which in practice comes down to PEAP-MSCHAPv2, which is deprecated and should be avoided whenever possible.
So you should not need to join the AD domain, unless you ignore the recommendations to phase out MS-CHAPv2.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Jun 16, 2023 02:36 AM
From: christian.chautems@swisscom.com
Subject: ClearPass 802.1x authentication AD necessary to Join domain or not?
Hello,
Joining AD domain is only required when using PEAP (not recommended anymore !!). If using EAP-TLS it is not needed
Kind regards
Christian Chautems
Original Message:
Sent: Jun 12, 2023 10:14 PM
From: ariyap
Subject: ClearPass 802.1x authentication AD necessary to Join domain or not?
if you want to use AD as an authentication source then ClearPass needs to join the domain to be able to authenticate users and provide further authorisation.
For TACACS, you might be using local auth source which is the local user db for authentication.
------------------------------
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.