> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-posture-management-insights/ise-weak-auth-method.md).

# ISE Weak Network Authentication Method

Detects users authenticating to Cisco ISE using weak or cleartext authentication protocols such as PAP, CHAP, MSCHAPv1, or EAP-MD5. These protocols transmit credentials with minimal protection, making them vulnerable to interception and replay attacks. Certificate-based methods like EAP-TLS or PEAP provide significantly stronger security.

**Recommended Actions**

Configure ISE authentication policies to require EAP-TLS, PEAP, or EAP-FAST for all network access. Disable PAP, CHAP, MSCHAPv1, and EAP-MD5 in the allowed protocols configuration for your policy sets. Investigate whether the weak authentication is caused by legacy devices that cannot support stronger protocols and plan their replacement.

**Compatibility**

Cisco ISE
