skip to content

802.1X enforcement is eight weeks away and the asset register lists 4,200 endpoints — why is that the wrong number to plan enrolment against, and what does the leftover exception list hand an attacker?

level: seniorimportance: should knowfreq 45%

answer

  1. purchase records versus what appears on a port
  2. watch before you block
  3. two gaps, opposite directions
  4. the residue is the finding
  5. exceptions with no expiry never shrink

basics

~20 s

The register lists what someone recorded, not what is on the wire. Plan against devices observed authenticating while 802.1X runs without blocking. Whatever you never found becomes a standing exception, a permanent unauthenticated way in.

solid answer

~50 s

An asset register is a record of purchases and builds; the enrolment denominator is the set of devices that actually appear on access ports. Get it by running 802.1X in a non-blocking mode first, so supplicants attempt authentication and failures are recorded rather than enforced, and reconcile that against switch address learning. Two gaps fall out. Register entries that never appear are dead capital — retire them, do not enrol them. Devices that appear but are not in the register are the dangerous set: unowned, unmanaged, and often long-lived. Each one must be enrolled, retired, or deliberately handed to the no-supplicant fallback design with a named owner. What you must not do is bulk-exempt whatever is left to protect the date, because an exception written to hit a deadline is never reviewed, and a permanent unauthenticated port is exactly the seam an attacker plugs into.

go deeper

for a junior

Know that the list of devices you must enrol comes from what actually appears on the network, not from a spreadsheet of what was bought, and that the two never match.

for a middle

Explain how a non-blocking 802.1X phase produces the real inventory: supplicants attempt authentication, outcomes are recorded, nothing is dropped, and switch address learning catches devices that never try.

for a senior

Show the judgment: how long you observe and why, how each discovered device is resolved before cutover, and why you would slip a date rather than ship a permanent exception list.

for a principal

Own the argument that the enrolment programme's second deliverable is an inventory the business has never had, and that unexpiring exceptions are a liability someone must accept by name.

## Why the register is the wrong denominator An asset register answers a finance and procurement question: what did we buy, and who was it issued to. Enrolment answers a different one: **what will present itself on an access port after cutover**. Those sets diverge in both directions in every estate, and the divergence is not noise — in a typical mid-sized environment it is a double-digit percentage. - **In the register, never on the wire.** Retired kit nobody deregistered, laptops in a drawer, spares, devices written off in a merger. Enrolling these wastes the scarcest thing you have, which is per-device touch time. - **On the wire, not in the register.** Machines rebuilt under a different name, a departed team's lab kit, contractor equipment, a device someone plugged in years ago that has quietly worked ever since. This set is where the interesting answers are, and it is the set the register can never give you. ## How to build the real number Run the control before you run the control. Enable 802.1X in a monitoring or non-blocking posture: supplicants attempt authentication, the authentication server records the attempt and its outcome, and a failure does not drop the device. Left running for a few weeks it produces the artefact this whole exercise turns on — **the set of devices that have actually appeared on a port, with what they tried to present**. Cross-check it against address learning on the access switches, which catches devices whose supplicant never even attempts an exchange. One thing to be honest about: the observation window has to cover the estate's real cycle. Monthly contractors, quarterly audit kit and the device that only appears when a particular room is booked will not show up in a fortnight, and each one you miss becomes a cutover incident. Say so when you present the plan. ## Resolving what you found Every observed device has to land in exactly one of four buckets before the date: | Bucket | Action | Cost | |---|---|---| | Enrolled | credential delivered through the management channel | one touch | | Retired | removed from the estate, port disabled | small, and permanent | | No supplicant | handed to the deliberately narrow fallback design, with an owner | ongoing review | | Unknown owner | investigated before cutover, never after | the expensive one | The fourth is the one programmes get wrong. An unowned device that has been on the wire for three years is not evidence of an intrusion by itself, and it is not proof of innocence either. What it certainly is, is a device nobody patches, nobody monitors, and nobody will notice being replaced — which is exactly the profile an attacker wants for a persistent foothold. Enforcement day is the only moment when the organisation is motivated to find out what it is; after cutover the motivation collapses, because it either works or it has an exception. ## Why the leftover exception list is the finding When the date is fixed and the enrolment count is short, the pressure is to write a blanket exemption: these ports, these addresses, these VLANs, admitted without authentication so the date holds. Understand what you have produced. It is a documented list of positions in your network where the admission control you just bought does not apply, and it has three properties that make it durable: 1. It was created under time pressure, so nobody recorded why each entry is on it. 2. It has no expiry, because an expiry would have reopened the argument about the date. 3. It is invisible in normal operation — everything works, which is what an exception is for. An attacker does not need to defeat 802.1X on an estate that carries one. They need to find one of these positions, and finding them is cheap: the ports that stayed up when the estate cut over are self-identifying to anyone with physical access. The counter-move that costs almost nothing is to make every exception **dated and attributed** — an owner, a reason, an expiry — and to accept a smaller number of exceptions with an honest slip in the date rather than a larger number that never shrinks. ## What to say in the interview Give the number you would plan against and where it came from, name the two directions the register is wrong in, and be explicit that the enrolment programme produces an inventory as its second deliverable — often the more valuable one. Then say what you do with the residue, because the residue, not the enrolled majority, is what decides whether the control means anything a year later.

  • How long should the non-blocking observation run before you commit to a number?
    Long enough to cover the estate's slowest cycle — monthly contractors, quarterly audit kit, seasonal or room-bound equipment. A fortnight flatters the count and produces cutover incidents; six to eight weeks is a common honest window. Say explicitly which populations your window cannot have seen, so the residual risk is a stated assumption rather than a surprise.
  • You find a device on the wire that nobody in the business will claim. What do you do?
    Treat it as unknown, not as malicious and not as fine. Establish what it talks to and who depends on it before cutover, while the organisation still cares. If no owner emerges, the safe outcome is to let enforcement remove it and see who complains — that is a controlled discovery on a day you chose, which is far better than granting it a permanent exception nobody reviews.
  • The date cannot move and you are 300 devices short. What do you propose?
    Enforce by area rather than exempt by list: cut over the segments that are fully enrolled and keep the unfinished ones on the observation posture with a dated finish. That preserves the meaning of enforcement where it applies and keeps the shortfall visible, instead of shipping the whole estate on time with a permanent set of unauthenticated positions inside it.

saying these in an interview costs you the question

  • Plans enrolment straight off an asset register export
  • Skips the non-blocking observation phase to save time
  • Bulk-exempts the leftovers to protect the cutover date
  • Writes exceptions with no owner and no expiry
  • Treats an unclaimed long-lived device as automatically benign

context