Latest / The Windows Podcast with Fexingo: Microsoft, PC, and Enterprise Windows Conversations / How Windows 11 Is Making Enterprise Wi-Fi More Secure
Transcript
- Lucas: Microsoft is quietly pulling the plug on an old Wi-Fi security standard, and if you work in enterprise IT, you probably have devices still relying on it. Luna: You're talking about TKIP, right? The older encryption protocol that's been hanging around since the early 2000s. Lucas: Exactly. TKIP — Temporal Key Integrity Protocol — was introduced as a stopgap back when WPA2 was first rolling out, to patch the flaws in the original WEP. But it's been considered weak for years now. The Wi-Fi Alliance deprecated it way back in 2014. Luna: Right, and most consumer routers moved on. But enterprise is always slower to sunset these things. Lucas: Much slower. And now Microsoft is forcing the issue. In the latest Windows 11 Insider Preview — build 26257, released just a couple of weeks ago, early June 2026 — they started blocking connections that use TKIP. If a Wi-Fi network only offers TKIP, Windows 11 will simply refuse to connect. Luna: So no fallback. If your access point doesn't support at least WPA2 with AES, or WPA3, you're locked out. Lucas: Correct. And this is going to hit a lot of enterprises in unexpected places. Think about older devices that connect to Wi-Fi — badge scanners, handheld inventory terminals, medical equipment like infusion pumps. A lot of those are still running on tkip only networks because the hardware is old and never got firmware updates to support AES. Luna: I've heard from IT admins in healthcare who say some of their patient monitors are still on Windows Embedded 7, and the Wi-Fi chips only speak TKIP. They're going to have a real problem. Lucas: That's exactly the kind of scenario. And Microsoft's timeline is not generous. The change is in the Insider Preview now, but the expectation is it'll roll into the 24H2 release later this year. So enterprises have maybe six months to audit their networks and either upgrade access points or isolate those legacy devices onto a separate SSID that still allows TKIP — if Windows allows that. Luna: Wait — can you run a separate SSID with TKIP? Or does Windows block any network that uses it? Lucas: From what I've read in the preview documentation, the block is at the connection level. If a network profile is set to use TKIP, Windows 11 won't associate. Period. So even a separate SSID would need to offer at least AES as an option. Mixed mode — TKIP plus AES — should still work because the client can choose AES. But if the network is tkip only, no go. Luna: That's actually a pretty smart approach from Microsoft. It forces the network to support modern encryption, but doesn't break backwards compatibility entirely — as long as the AP offers both. Lucas: Right. And honestly, TKIP has been insecure for a decade. There are known attacks — like the Beck-Tews attack — that can recover the key in under 15 minutes. In a regulated industry, running TKIP is probably a compliance violation already. So this is overdue. Luna: But let's be real — for the IT admin who has 200 badge scanners that don't support AES, this is a headache. They have to replace hardware, or at least update firmware, and that costs money and time. Lucas: Absolutely. And that's where the planning comes in. The first step is to audit every Wi-Fi network in the organization — check the security settings on each SSID. If any of them are set to tkip only, you need to change them to AES or WPA3. Then test the devices. You'll probably find a few that drop off. Luna: And for those devices, you may need a separate IoT network that still uses TKIP — but then you're running an insecure network, which is not ideal. Maybe you segment it tightly. Lucas: That's the workaround. Put those devices on a VLAN with no internet access and only the minimum server connectivity they need. But honestly, the better solution is to replace the hardware. TKIP is ancient. And if you're in healthcare or finance, you're probably due for an audit anyway. Luna: Speaking of audits — this is exactly the kind of practical, nuts and bolts conversation that keeps this show ad-free and listener-supported. If today's tech talk gave you something usable, consider tossing a few bucks our way at buy me a coffee dot com slash fexingo. It helps us keep digging into these enterprise pain points. Lucas: Yeah, no pressure at all. Just if you find value, it's appreciated. Anyway — back to the migration. The other thing IT admins need to check is whether their access points support WPA3. A lot of older enterprise APs from 2015-2018 might only do WPA2 with AES. That's fine for now, but WPA3 brings better security — especially in enterprise mode, with 192-bit encryption and protection against offline dictionary attacks. Luna: WPA3-Enterprise 192-bit mode is actually mandatory for some government contracts, isn't it? Like for US federal agencies. Lucas: Yes, the NSA's Commercial National Security Algorithm suite requires it. So if you're dealing with any kind of classified or sensitive data, you should already be on WPA3. But for most commercial enterprises, WPA2 with AES is still acceptable — for now. Microsoft's deprecation of TKIP is just the first step. I expect they'll phase out WPA2 entirely in the next few years. Luna: That would be a much bigger migration. But let's focus on the immediate: what should an IT admin do this week? Lucas: Three things. One: audit all SSIDs. Use a wireless survey tool or just check the controller settings. Two: change any tkip only networks to AES or WPA3. Three: test connectivity for all critical devices, especially IoT and medical gear. If something breaks, you have options: update firmware, replace the device, or create a segmented legacy network. Luna: And if you're on Windows 10, does this affect you? Windows 10 is still supported until October 2025, but I assume Microsoft will eventually backport this change? Lucas: Microsoft hasn't announced anything for Windows 10 yet. But given that Windows 10 is in its final year of support, I wouldn't expect them to add new restrictions there. The focus is on Windows 11. So if you're still on Windows 10, you might be using TKIP without knowing it — and when you upgrade to Windows 11, you'll hit the block. Luna: So this is another reason to test your Windows 11 deployment carefully. Not just apps and drivers, but your entire network stack. Lucas: Exactly. And it's not just Wi-Fi. There are other networking changes coming in 24H2 — like deprecating the old SMB 1.0 protocol by default. But we can cover that another time. Luna: Yeah, that's a whole other episode. For now, the takeaway: check your Wi-Fi security, move off TKIP, and don't let your badge scanners catch you off guard. Lucas: Pretty much. And if you need to dig deeper, Microsoft has a support article on the deprecation — KB5040550 — that lists all the details. We'll link it in the show notes. Luna: Alright, that's a solid plan. Next time we might look at what happens when Microsoft finally kills off NTLM in favor of Kerberos. There's been chatter about that. Lucas: That's another big one. But for now, check your TKIP, and we'll talk next time.