Skip to content

Network access · cloud RADIUS

Wi-Fi and VPN that check the certificate. Not a password.

Radius365 runs the RADIUS servers your access points, switches and VPN gateways talk to. Devices authenticate with the certificates Intune already pushed from your Radius365 CA (EAP-TLS); the ones that cannot hold a certificate are admitted by MAC address (MAB). Policies decide the VLAN — by certificate, SSID, Entra group or Intune compliance. No NPS, no on-premises RADIUS, no shared password on the SSID.

Setup path4 stages
Side by side9 capabilities
Answered7 FAQ

The problem

Enterprise Wi-Fi usually ends with a server nobody wants to own.

802.1X is the right answer for corporate networks. The RADIUS server behind it is where projects stall.

  • 01

    An NPS box per site

    Network Policy Server needs a domain-joined Windows server, patching, a certificate of its own and someone who remembers how its policies are ordered. Branch offices get a second one, or a slow link to the first.

  • 02

    Passwords over the air

    PEAP/MSCHAPv2 sends the domain password through the access point. An evil-twin SSID collects it; a phishing-resistant sign-in policy is undone by the Wi-Fi.

  • 03

    Cloud-only devices, on-prem RADIUS

    Entra-joined laptops and Intune-managed phones have no line of sight to a domain controller. A RADIUS server that validates against Active Directory cannot see them.

  • 04

    No trail when something breaks

    Why did a laptop land on the guest VLAN at 08:52? NPS event logs, a syslog server and a spreadsheet of MAC addresses are how the question usually gets answered.

How it works

From the portal to an Access-Accept in four steps.

Network access is a page in the Radius365 portal, on the same subscription as your certificate authorities. There is nothing to install.

  1. 01STEP 1 / 4

    Register the NAS

    Add each access point, wireless controller, switch or VPN gateway as a RADIUS client: its public source addresses for UDP (one client can list a main and a backup Internet line), or its certificate thumbprint for RadSec. The shared secret is generated for you and shown once.

  2. 02STEP 2 / 4

    Point the network at two servers

    Configure srv01.radius365.org and srv02.radius365.org on the NAS — UDP 1812/1813 or RadSec on TCP 2083 — as primary and secondary. They run in different availability zones of the EU region; the NAS fails over by itself.

  3. 03STEP 3 / 4

    Write the policies

    First match wins. Conditions: issuing CA, certificate SAN (UPN, DNS name, a URI tag you put in the SCEP profile), certificate subject, SSID, RADIUS client, MAC address, Entra group membership, Intune compliance state. The action is Accept with a VLAN and optional attributes, or Reject.

  4. 04STEP 4 / 4

    Push the Wi-Fi profile

    An Intune Wi-Fi profile with EAP-TLS, the client certificate from your SCEP profile and the Radius365 trust anchor as the server root. Devices connect; the journal shows every attempt — identity, device OS, SSID, decision, policy, VLAN and which server answered.

Read the network access guide in the help center →

Side by side

NPS on-premises versus Radius365 cloud RADIUS.

The same 802.1X on the network side; a different operating model behind it.

NPS on-premises versus Radius365 cloud RADIUS.
FeatureNPS on-premisesRadius365 cloud RADIUS No NPS
Servers to runOne or more Windows servers per site, domain-joinedNone — two managed servers in the EU region, zone-redundant
Authentication methodsPEAP/MSCHAPv2 (passwords), EAP-TLS with an enterprise CAEAP-TLS only (certificates from your Radius365 CA) and MAB for devices without a certificate — deliberately no password method
Identity sourceActive DirectoryThe certificate, plus Microsoft Entra ID groups and Intune compliance, read live
Cloud-only devicesNeed a line of sight to a domain controllerEntra-joined and Intune-managed devices work anywhere
TransportUDP with a shared secret; RadSec via third-party proxiesUDP 1812/1813 and RadSec (RADIUS over TLS, mutual authentication) on the same servers
Policy conditionsWindows groups, NAS properties, time of dayIssuing CA, certificate SAN/subject, SSID, RADIUS client, MAC, Entra group, Intune compliance; VLAN and RADIUS attributes on Accept
Revoked certificateDepends on CRL reachability from each NPSChecked against the issuing CA on every request — a revoked certificate is rejected immediately
VisibilityEvent log 6272/6273 per serverOne authentication journal in the portal with identity, OS, SSID, policy, VLAN and server; accepts and rejects in the audit log and SIEM export
LicensingWindows Server licence, CALs, the hardwareIncluded in the Enterprise plan (1,000 active identities per month); 50-identity preview on Premium

Network access is available today in the EU region. It authenticates certificates issued by your Radius365 CAs — bring-your-own-CA and password methods are out of scope by design.

FAQ

Questions about cloud RADIUS.

01Which network equipment works?

Anything that speaks RADIUS: enterprise access points and wireless controllers, managed switches, VPN gateways. UDP RADIUS needs the public source address of the NAS registered as a client; RadSec identifies the NAS by its certificate instead, so dynamic addresses and NAT are not a problem. Both servers answer on UDP 1812/1813 and TCP 2083.

02Is PEAP or username/password supported?

No, on purpose. Password-based Wi-Fi is the most common way corporate credentials are captured by a rogue access point, and it is exactly the problem certificates remove. Devices authenticate with EAP-TLS; devices that cannot hold a certificate (printers, sensors) are admitted by MAC address bypass under a policy you write.

03Where does the identity come from?

From the certificate the device presents — issued by one of your Radius365 CAs, typically through an Intune SCEP profile. The engine verifies the chain, validity and revocation status, then evaluates your policies. Policies can additionally ask Microsoft Entra ID whether the user or device is in a group, and Intune whether the device is compliant.

04How are VLANs assigned?

Each Accept policy can carry a VLAN id, sent as the standard Tunnel-Type / Tunnel-Medium-Type / Tunnel-Private-Group-ID attributes, plus optional attributes such as Filter-Id or Session-Timeout. Employees, phones, printers and quarantined devices can each land on their own VLAN from one SSID.

05What happens when a laptop is removed from Intune?

Intune asks Radius365 to revoke its certificate; the next authentication is rejected with the reason in the journal. Reissued certificates replace the previous one automatically, so a device keeps exactly one live certificate per profile.

06Which regions?

The RADIUS servers run in the EU region today (West Europe, two availability zones). Subscriptions in the US region see the feature as not yet available; the certificate services there are unaffected.

07What does it cost?

It is part of the Enterprise plan, with 1,000 active identities per month included — an identity is a user, device or MAC address that authenticated at least once in the month. Premium includes a 50-identity preview so you can test before upgrading.

Microsoft, Microsoft Intune, Microsoft Entra ID, Network Policy Server and Azure are trademarks of Microsoft Corporation. Radius365 PKI is an independent product and is not affiliated with or endorsed by Microsoft. Vendor names are used to describe interoperability only.

Turn the SSID password off for good.

Set up a RADIUS client, one policy and an Intune Wi-Fi profile on a test group — most teams see the first certificate-based connection the same afternoon.