Skip to main content
Offline·Progress is saved on this device and syncs the next time you open the app online.
Identity & Access Management

MSCHAP

Microsoft Challenge Handshake Authentication Protocol

A Microsoft authentication protocol using a challenge and response, now considered weak.

MSCHAP, and its successor MSCHAPv2, authenticate users with a challenge-response exchange so the password is not sent in cleartext, historically used with PPTP VPNs and wireless via PEAP. Its underlying cryptography is broken, allowing offline cracking of the response, so it must be tunneled inside TLS or replaced with stronger methods such as EAP-TLS. On the exam, treat MSCHAP as a legacy authentication protocol with known weaknesses. Pair it with the guidance to use certificate-based EAP methods instead.

Related terms

Looking MSCHAP up is step one. Getting tested on it is step two.

A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.

Not affiliated with or endorsed by CompTIA.