Windows AD - 802.1x

Hello all!

I'm an employee of an MSP and we have a customer that employs an 802.1x environment that is currently authenticating computers, etc to connect via being members of an certain security group in AD to an SSID. 


My question is, do I need to authenticate non-AD devices or do said devices just need to have the cert manually added? 

I believe I need to have the non-AD devices to authenticate first, as the authenticator is looking for the device names to check against AD. 


I don't think bypassing and just putting the cert on the non-ad devices will work. 




