We use 802.1X with certificate-based EAP-TLS authentication on Windows 11 laptops for both wired and wireless access. On several laptop models, the built-in Ethernet adapter fails with the message, "A certificate could not be found that can be used with EAP." However, the same laptops authenticate successfully when connected through a docking station or USB-C Ethernet adapter. The wired authentication policy is deployed through Group Policy and appears to use the same settings for every adapter. Wireless authentication works normally, so the problem seems limited to the onboard wired NIC. What could cause this difference, and what should I check?
3 Answers
Look closely at the certificate selection rules. If several client certificates are installed and EAP is using basic automatic selection, Windows may fail to choose a usable certificate for one adapter while another adapter happens to work. Tightening the certificate requirements—such as intended purpose, issuer, or authentication type—can make selection reliable.
First, verify that the onboard adapter is enabled and that its 802.1X authentication setting is turned on. It’s worth checking both the NIC properties and the wired auto-configuration settings, since the dock and USB-C adapter may be receiving different per-interface configuration.
This can also be specific to certain laptop models, NIC drivers, or firmware. Since HP and Lenovo systems have shown similar wired 802.1X quirks, compare the onboard adapter driver and advanced properties with the working dock adapter, then test updated NIC drivers and firmware. The fact that Wi-Fi works does not rule out a wired-driver or adapter-specific issue.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures