Latest / The Windows Podcast with Fexingo: Microsoft, PC, and Enterprise Windows Conversations / How Windows 11 Is Quietly Mandating Enterprise Wi-Fi Password Rotation
Transcript
- Lucas: Luna, I want to talk about something that's been quietly rolling out in Windows 11 enterprise builds, and it's going to make a lot of network admins sit up. Microsoft is essentially mandating Wi-Fi password rotation in managed environments. Luna: Wait — automatic password rotation for Wi-Fi? Isn't that something you usually handle with a RADIUS server and certificate-based authentication? Lucas: Exactly right. The gold standard is 802.1X with certificates. But the reality is that a lot of small to midsize businesses still use pre-shared keys — a single Wi-Fi password for the whole network. Windows 11 is now pushing Group Policy settings that force a rotation of that PSK every 30 days. Luna: So Microsoft is essentially saying, if you're using a shared password, you can't just set it and forget it anymore. Lucas: Correct. And it's tied to the Wi-Fi Protected Access 3 standard — WPA3. Windows 11 has a new policy called 'WPA3-Personal PSK Rotation Period' that you configure under Computer Configuration > Administrative Templates > Network > WLAN Service > WLAN Settings. Set it to 30 days, and the client expects the network to change the password every month. Luna: I imagine that creates a coordination problem. The network itself has to change the password at the same interval, or clients get locked out. Lucas: That's the crux. If you set this policy on your Windows 11 devices but your access points are still on the old password, every 30 days you'll have a flood of helpdesk tickets. The policy is really designed for environments that use a centralized controller — like a cloud-managed Wi-Fi system from Aruba, Meraki, or Ruckus — where you can schedule automatic PSK updates. Luna: So it's less about Windows itself and more about how the whole network stack coordinates. What about hardware support? I thought WPA3 adoption was still spotty outside of newer access points. Lucas: That's been a barrier. According to the Wi-Fi Alliance, as of early 2026, about 65 percent of enterprise access points sold in the last two years support WPA3. But the installed base is much lower — maybe 30 percent. So if you're running older Cisco or Ubiquiti gear, you might not even have the option to rotate the PSK programmatically. Luna: And Windows 11 doesn't force you to use WPA3, right? The policy only applies if the network advertises WPA3 capability. Lucas: Correct. If your network is still on WPA2, this policy is essentially ignored. But Microsoft has been clear that WPA2 is deprecated starting with Windows 11 version 24H2. The next feature update may disable WPA2 by default on new enterprise installs. Luna: That's a big shift. For companies that have been running the same Wi-Fi password for years, this is going to force a network refresh or a move to certificate-based authentication. Lucas: Right. And Microsoft's endgame is clearly zero-trust networking. They want every device to authenticate with a unique credential — either a certificate or a passkey tied to the user's identity. The rotating PSK is a stepping stone, but it's not the destination. Luna: It does raise a practical question: if you rotate the PSK every 30 days, how do you distribute the new password to non-Windows devices? Guest devices, IoT sensors, printers? Lucas: That's the weak spot. Microsoft's policy only covers managed Windows 11 clients. For everything else, you'd need a separate SSID with a static password, or use a captive portal. Some network vendors have solved this with QR code generation or email distribution, but it's not built into Windows. Luna: So IT admins need to plan for a phased rollout. Maybe start with a pilot group of Windows 11 devices, test the rotation, then expand. Lucas: Absolutely. And Microsoft does provide a grace period setting — you can configure the policy to accept the old password for up to 72 hours after rotation, which gives users time to get the new one. But that grace period is also a security window. Luna: Speaking of security, does this policy actually improve security? I mean, rotating a shared password every 30 days still leaves you vulnerable if an attacker gets the password on day one. Lucas: You're right — it's not a silver bullet. The real benefit is reducing the blast radius if a password leaks. In the old model, a leaked PSK could be used for months. Now it's valid for at most 30 days. But Microsoft's documentation explicitly says this is a 'transitional measure' toward 802.1X. Luna: And for companies that can't move to certificates — maybe because they have legacy devices — this is a middle ground. Lucas: Exactly. Look, I think the quiet mandate here is about habit. Microsoft is training IT departments to think of Wi-Fi credentials as ephemeral. Once you're used to rotating the PSK every 30 days, the jump to per-device certificates feels smaller. Luna: That's a good way to frame it. I want to get into the implementation details — what exactly does an admin need to configure? Let's start with the actual Group Policy path. Lucas: Sure. The policy is called 'Specify WPA3-Personal PSK rotation period' and it's under Computer Configuration > Policies > Administrative Templates > Network > WLAN Service > WLAN Settings. You enable it and set the number of days — I'd recommend starting with 60, not 30, to give users a transition period. Luna: And then on the network side, you need to configure the access point controller to rotate the PSK on the same schedule. Most enterprise controllers have a 'PSK rotation' setting under the WPA3 security profile. Lucas: Right. Meraki, for instance, has a 'PSK rotation interval' in the SSID settings. Aruba has it under 'WPA3-Personal configuration'. The key is making sure both sides agree on the rotation date. If they get out of sync, you'll have devices that can't connect. Luna: One thing that's not obvious: what happens to devices that are offline during the rotation? Say a laptop that's been in a drawer for a week. Lucas: When it comes back online, it will try the old password. If the grace period has expired, it fails. Then Windows 11 prompts the user for the new password — but if the user doesn't know it, you're stuck. That's why some admins combine this with a self-service portal where users can retrieve the current PSK. Luna: Or you could use a network access control solution that dynamically provisions the password via 802.1X. But then you're back to certificates. Lucas: Right. I think the real takeaway for IT admins is: don't flip this switch overnight. Test with a small group, monitor the logs, and have a rollback plan. Microsoft's policy is powerful, but it's unforgiving if you misconfigure it. Luna: We should also mention that this policy is only available in Windows 11 Enterprise and Education editions. Pro and Home don't have it. Lucas: Good point. So this is squarely aimed at managed organizations. If you're running Windows 11 Pro on a BYOD network, you won't see this setting. Luna: And I imagine it integrates with Windows Autopilot and Intune, so you can push the policy from the cloud. Lucas: Yes, it's available as a CSP — configuration service provider — under the Wi-Fi policy in Intune. So if you're managing devices with Microsoft Endpoint Manager, you can deploy this without touching on-premises Group Policy. Luna: That makes it easier for organizations that have already moved to cloud-native management. Lucas: And that's the direction Microsoft is pushing — everything managed through Intune, zero-trust network access, no shared secrets. The rotating PSK is a relatively small policy, but it's part of a much larger architecture. Luna: You know, talking about these quiet mandates, it's interesting how Microsoft uses them to nudge enterprises toward security best practices without forcing a hard cutover. Lucas: It's a pattern we've seen across Windows 11. Group Policy Preferences deprecated, SMB1 disabled, NTLM being phased out. Each one is a gentle push, but together they're reshaping how IT operates. Luna: And if this conversation gave you something practical — like a new policy to test or a reason to check your WPA3 support — that's exactly the kind of thing that keeps this show going. We do this ad-free, and listener support is what makes that possible. If you find value in these deep dives, you can buy us a coffee at buy me a coffee dot com slash fexingo. Lucas: Yeah, every contribution helps us keep digging into these quiet changes that affect real IT work. And speaking of digging, I want to look at one more angle: how this policy interacts with Windows 11's Wi-Fi Sense and password sharing features. Luna: Oh, that's a good point. Wi-Fi Sense used to share passwords with contacts — but I think that was removed in Windows 10. Lucas: It was. But there's still a feature in Windows 11 called 'Share Wi-Fi passwords via QR code' in the network settings. If you rotate the PSK, every QR code becomes stale after 30 days. So users who shared a QR code with a visitor will need to generate a new one. Luna: That's a small but practical annoyance. For a guest network, you'd probably want a separate SSID without rotation. Lucas: Exactly. So the recommendation is: use rotation only on internal corporate SSIDs, not guest networks. And make sure your visitor management system doesn't depend on a static PSK. Luna: Alright, so to wrap up: if you're an IT admin, check your access point firmware for WPA3 support, test the policy in a lab, and plan for a gradual rollout. And if you haven't moved to 802.1X yet, this might be the nudge you need. Lucas: Good summary. And as always, we'll keep tracking these quiet Windows 11 changes so you don't have to.