Connect the identity sources you already use, from Active Directory and LDAP to cloud providers like Microsoft Entra ID and Google Workspace.
Passwordless access with certificates and Passpoint, plus multi-factor authentication.
Policies for every access level, based on who the user is and which groups they belong to.

Authenticate users against Active Directory, LDAP, SQL databases and other identity sources you already have.
Connect cloud identity providers such as Microsoft Entra ID and Google Workspace, with RADIUS in the cloud or on-premises.
Changes in your directory apply on the network automatically: new users get access, and users disabled in your directory lose it.
Users and devices connect with certificates or Passpoint profiles, with no passwords to type, share or steal.
We issue and renew the certificates your users and devices need for EAP-TLS, so you don't have to run your own certificate authority.
Require a second verification factor on top of the password for stronger protection of network access.
Apply different policies based on group membership, such as speeds, quotas and the hours users can connect.
Place users on different VLANs based on their directory groups, to keep traffic separated.
Set expiry dates on accounts, and revoke one user's access when they leave without affecting anyone else.
Lock an account to specific devices by MAC address, so credentials can't be used on other devices.
Change a live session's access or disconnect a user instantly with Change of Authorization (CoA).
Keep detailed authentication and session logs, so you always know who connected, when and from where.
Stronger security and a smoother experience, with no passwords to type, share or steal.
With EAP-TLS, devices authenticate with digital certificates instead of passwords, for the strongest, phishing-resistant security.
A profile installed once, through your mobile app or MDM, connects devices automatically and securely from then on.
Never trust, always verify. Every connection is tied to an identity and gets only the access it needs.
Every user and device proves its identity with its own credentials, certificate or profile. Nothing is trusted just for being on the network.
Users get only the access their role needs, based on their identity and group membership.
Separate VLANs for different groups and devices keep traffic apart and limit what each one can reach.
Access changes as soon as an identity does: CoA updates or ends live sessions, and every connection is logged.
On-premises directories such as Active Directory and LDAP, and cloud identity providers such as Microsoft Entra ID and Google Workspace.
Users sign in with the accounts they already have, so there's no separate user database to maintain.
Let users sign in to WPA-Enterprise Wi-Fi with their Google Workspace accounts. See how with FreeRADIUS and Secure LDAP
Assign VLANs and policies based on directory groups. See how with Google Workspace Secure LDAP
Don't see your identity source? We can integrate with others too. Talk to us
From offices to campuses and venues, the right people get the right access.
Staff sign in with their Active Directory or Entra ID accounts, with access based on their role and devices on their own VLAN.
Different access for students, staff and guests, driven by group membership in your directory.
Every resident gets their own credentials and service tier, and access ends automatically when they move out.
Guests get their own access for their stay, which is decommissioned when they leave.
Loyalty app members connect automatically and securely with Passpoint every time they visit.
Subscriber identities tied to their plans, with speeds, quotas, IP assignments and expiry dates.
Companies all over the world are using our products and services
Common questions about identity and access management for your network.
It means every user and device connects with its own identity, checked against your identity source, and gets access based on who they are: the right network, speed, time limits and policies, instead of one shared password for everyone.
Active Directory, Microsoft Entra ID, Google Workspace, LDAP and SQL databases, among others. If your identity source isn't listed, get in touch: we can integrate with other identity sources too.
Yes. We integrate with cloud identity providers such as Microsoft Entra ID and Google Workspace, and our RADIUS servers can run in the cloud or on your premises.
Devices authenticate with digital certificates (EAP-TLS), which we can issue and renew for you, or with a Passpoint profile installed once through your mobile app or MDM. Either way, there are no passwords to type, share or steal.
Yes. Policies can be based on user or group membership, including VLANs, rate limits, time and volume quotas, time-of-day access and simultaneous use limits.
You revoke that user's access, or let it end automatically on an expiry date. With CoA, an active session can be disconnected immediately, and nobody else is affected.
Yes. You can require a second verification factor on top of the password for stronger protection of network access.
Yes. Detailed authentication and session logs, with reporting on users, sessions and usage.
Yes. Changes in your directory apply on the network automatically: new users get access, and users disabled in your directory lose it.
Yes. Every user and device is verified with its own identity, gets only the access its role needs, and is kept on its own network segment. Access is re-evaluated as identities change, and every connection is logged.