Every user and device connects with their own credentials or certificate, instead of one shared password.
WPA2/WPA3-Enterprise encryption, with EAP-TLS, PEAP, EAP-TTLS and other EAP methods.
Backed by our cloud or on-premises RADIUS, connected to the user directories you already use.

Every user connects with their own credentials instead of one shared password, so you always know who's on your network.
Authenticate devices with digital certificates instead of passwords, for stronger, phishing-resistant security.
Every connection is authenticated and encrypted with the latest enterprise Wi-Fi security standards.
Disable one user's access when they leave, without changing a password for everyone else.
Authenticate users against the directories you already use, so there's no separate user database to maintain.
Place users on different VLANs and apply different policies based on their directory groups.
Require a second verification factor on top of the password for stronger protection of network access.
Change a live session's policy or disconnect a user instantly with Change of Authorization (CoA), with no reconnect needed.
Keep detailed authentication and session logs, and report on users, sessions and usage.
Run RADIUS in the cloud for multi-site networks, or on your own servers to keep authentication inside your network.
The most common 802.1X methods, and others when you need them. Choose what fits your users, devices and security requirements.
Certificate-based authentication on both the client and the server. The strongest option, with no passwords to steal.
Username and password sent inside an encrypted TLS tunnel. Widely supported and easy to roll out.
Username and password inside a TLS tunnel, with flexible inner authentication methods for different directories.
Need something else? We can work with other EAP methods your devices or network require.
Users connect with their existing directory credentials, so there's no separate Wi-Fi account to create or maintain.
Integrations with SQL databases, Google Workspace, LDAP, Active Directory, Microsoft Entra ID and other identity providers.
Let users sign in to WPA-Enterprise Wi-Fi with their Google Workspace accounts. See how with FreeRADIUS and Secure LDAP
Assign VLANs and policies based on directory groups. See how with Google Workspace Secure LDAP
Don't see your directory? We can integrate with other identity sources too. Talk to us
Use 802.1X for staff, and combine it with other methods for guests and devices.
A branded sign-in page for visitors, with click-through, OTP, vouchers, payment and more.
A unique Wi-Fi password for each user or device, including devices that don't support 802.1X.
Push Passpoint profiles to company devices through your MDM, so staff connect automatically and securely.
Companies all over the world are using our products and services
Common questions about 802.1X and WPA-Enterprise Wi-Fi.
802.1X is the standard behind WPA-Enterprise Wi-Fi. Instead of one shared password, each user or device signs in with their own credentials or certificate, which a RADIUS server checks against your user directory before granting access.
With a shared password (WPA-Personal), everyone uses the same key and you can't tell users apart. With 802.1X, every user has their own credentials, so you can see who's connected, apply policies per user or group, and revoke one person's access without affecting anyone else.
We support EAP-TLS for certificate-based authentication, plus PEAP and EAP-TTLS for username and password logins inside an encrypted tunnel. We can also work with other EAP methods your devices or network require, and we'll help you pick the right one.
Yes. With EAP-TLS, devices authenticate with digital certificates instead of passwords, which gives the strongest, phishing-resistant security.
SQL databases, Google Workspace, LDAP, Active Directory and Microsoft Entra ID, among others. If your directory isn't listed, get in touch: we can integrate with other identity sources too.
Yes. Users can be placed on different VLANs and given different policies, such as rate limits, based on their directory groups.
Cloud RADIUS suits networks spread across many locations and avoids running server hardware. On-premises RADIUS keeps authentication and user data inside your own network. We'll help you choose based on your requirements.
Devices such as smart TVs, printers and IoT devices can use xPSK instead, with a unique password for each device. Many networks combine 802.1X for staff with xPSK for devices and a captive portal for guests.