
I have a 2012R2 CA and 2012R2 NPS server. So, I know this discussion has been inactive for quite some time but I'm running out of online reading material and this guide is the closest I've got. For Wi-Fi, just toggle it off and back on again from the menu bar. You should get connected and authenticated to your network with no certificate prompt. Hit Disconnect, wait a few seconds, then hit connect. There should be an 802.1x section with a handy "Connect/Disconnect" button.

Now that you only have one machine certificate, go to System Preferences > Network. The one that expires last will be the most recently issued certificate and the one you want to keep. Find the certificate for with the expiration date farthest in the future and delete the others. Open Keychain Access (Applications > Utilities > Keychain Access), click on the System keychain, then limit your view to only Certificates. Or you can just fix the multiple certificate problem, which would be the preferred way to go.

If not, remove that saved preference from Keychain Access and try the next certificate. When you do that preference will be saved and it should just work. OS X can't figure out which cert to use in this case, so it asks you to pick one. Perhaps your MDM solution applied the profile multiple times.

For some reason you have multiple machine certificates in your Keychain when you should only have one. Nice tutorial, very nice! Do you have experience with USB/Thunderbolt to RJ45 adapters? I followed everything here and got authenticated (with a normal ethernet-port)!!! Never thought i'll get this.
