Hello,
We are playing around with Central/AOS 10. I am looking at MPSK in particular. As I understand it there are two types (excuse me if I get the terminology wrong here):
Personal (user-managed) MPSK - the user obtains their MPSK by visiting an onboarding URL (logging in via eg EntraID). This MPSK is unbound, ie can be used on multiple devices, devices do not need to be MAC-registered. The MPSK is linked to the username that was used when onboarding. As far as I can see these cannot be generated via the API
Named MPSK - can be generated via GUI or API, these are also unbound and are not linked to a 'real' username (ie no auth happens with the username)
I am trying to test Personal MPSK, but I don't know how to configure it. When I try to set up an MPSK WLAN I can make it work with Named MPSK as the identity store but not my personal MPSK. Are there any docs explaining how to configure this? When a personal MPSK is created how is it linked to the username that was used to create it, is there a separate database in Central NAC for these? Are they accessible by admins, can they be managed? Could they be created by API?
Sorry for all the questions, this is all quite new!
Guy
-------------------------------------------