Exactly, so whatever you are doing to attempt a role mapping isn't working. Not having direct experience with this exact setup, I'm going to guess your attempt to map the Test_Teap_... role isn't actually supported as part of the Entra ID integration. Machine authentications should be happening with an Intune attribute check.
Original Message:
Sent: May 20, 2024 02:46 PM
From: OumarCisse
Subject: EAP-TEAP Wired User
@chulcher sorry about the confusion.
Step 2 is that when it get Test_Teap-machine_auth

This is step 1 and 2. Clearpass is putting it into Other which has a policy to reject.

Original Message:
Sent: May 20, 2024 02:37 PM
From: chulcher
Subject: EAP-TEAP Wired User
- When the computer turns on and initially connects, there should be an entry in the access tracker.
- When you login to the machine, there should be another entry in the access tracker.
- When you log back out, there should be another entry in the access tracker.
Steps 1 and 3 should have the same result. All three steps should be resulting in some role mapping happening. You just said "not getting any role". So, what roles are getting assessed and assigned to the sessions?
------------------------------
Carson Hulcher, ACEX#110
Original Message:
Sent: May 20, 2024 02:29 PM
From: OumarCisse
Subject: EAP-TEAP Wired User
@chulcher My machine is in the Test_Teap_machine_auth role. When I log-in I hit the first one which is working but when I sign out, I should hit the second one. Correct?
Or I am going completely wrong about this.

Original Message:
Sent: May 20, 2024 02:21 PM
From: chulcher
Subject: EAP-TEAP Wired User
If no roles are getting assigned when only method 1 is successful, then I'm not seeing an enforcement filter in your screenshots that matches those conditions, which would result in the default action taking place.
------------------------------
Carson Hulcher, ACEX#110
Original Message:
Sent: May 20, 2024 02:17 PM
From: OumarCisse
Subject: EAP-TEAP Wired User
@chulcher
So it is not getting any role when I sign out but when I log in it gets the appropriate role.
Thanks
Original Message:
Sent: May 20, 2024 02:05 PM
From: chulcher
Subject: EAP-TEAP Wired User
What role(s), if any, are getting applied to the session?
------------------------------
Carson Hulcher, ACEX#110
Original Message:
Sent: May 20, 2024 01:44 PM
From: OumarCisse
Subject: EAP-TEAP Wired User
Thanks @jonas.hammarback for your feedback.
I have partially made it work. I have disabled auth requirement since every user is going to be on site.

Now, my enforcement profiles are not working properly. Clearness is rejected me even though, I am machine auth. I am not sure why for now.

I want to rely on enforcements for the rest of the configurations.
Original Message:
Sent: May 17, 2024 10:13 AM
From: jonas.hammarback
Subject: EAP-TEAP Wired User
Hi
From the screenshots of your policies I can't see anything related to the MAC addressen and they look OK as far as I can see.
One thing that came to my mind, if you check the Access Tracker for both the computer MAC address and the docking station MAC address, can you verify that the devices only hit the 802.1x service?
In the 802.1x sevrice, what authentication methods do you allow? EAP-TEAP should be the only authentication method in the service with your current role mapping and enforcement policies.
On the switch side, do you have a configuration performing MAC auth before the the 802.1x? In this case the docking station will first get a MAC authentication, probably with profiling, Slightly later the client will perform the 802.1x authentication, maybe this situation could cause issues. But it depends on how the switch prioritize between MAC authentication and 802.1x.
------------------------------
Best Regards
Jonas Hammarbäck
MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
Aranya AB
If you find my answer useful, consider giving kudos and/or mark as solution
Original Message:
Sent: May 17, 2024 09:38 AM
From: OumarCisse
Subject: EAP-TEAP Wired User
Hello @jonas.hammarback
Maybe that is a good idea. I could put a place a polices that evaluate when a device a marked unknown. I will look at that option.
Here are my enforcement and roles screenshots.


I already have devices sync from Intune. But when I pug into the dock, it gets a different Mac address from the dock ethernet card. So Clearness think it is a new device and does not know how to classify it. 
You can see from the screenshot that second one is known and the first one is from the docking station.
Thanks
Original Message:
Sent: May 16, 2024 10:24 AM
From: jonas.hammarback
Subject: EAP-TEAP Wired User
Hi
Can you share the configuration of your role mapping and enforcement policies? Do you have any condition in the policies that evaluates if the status is Known?
As Carson mentioned, the status should only have impact in some use cases with MAC authentication, like guest MAC caching.
------------------------------
Best Regards
Jonas Hammarbäck
MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
Aranya AB
If you find my answer useful, consider giving kudos and/or mark as solution
Original Message:
Sent: May 16, 2024 10:00 AM
From: OumarCisse
Subject: EAP-TEAP Wired User
Hello Guys,
I have configured Teap successfully on wireless. Thank you everyone for their input. I am facing a new problem on the wire side.
At my company we use docking station to plug in our ethernet cable and the docking station as a different MAC address than the wireless one. Every time I tried a new dock,
Clearpass associated the host name to the dock Mac-address but it come up as unknown in the endpoint.
Unless, I make that Mac-address know, Clearness would always reject the computer on the TEAP config. Should I configure the teap differently because it is impossible to note
every docking station mac-address.
Any help would be appreciated.
Thanks