Zum Hauptinhalt springen

Can Microsoft Entra ID do RADIUS for WiFi?

Not on its own. Entra ID speaks SAML and OIDC, not the RADIUS protocol your access points use, so 802.1X WiFi needs a RADIUS service in between. Purple runs that service in the cloud. Staff sign in with their Entra ID account, receive a certificate-based WiFi pass, and connect over WPA2 or WPA3-Enterprise with no NPS server.

Why Entra ID needs a RADIUS layer

Enterprise WiFi authenticates with 802.1X: the access point wraps the device’s credentials in a RADIUS request and waits for a yes or no. Microsoft Entra ID does not listen for RADIUS or LDAP, and it does not hold reversible NTLM password hashes for cloud-only accounts. The PEAP-MSCHAPv2 pattern that on-premises Active Directory and Windows Server NPS supported for years has nothing to check against once identity lives in Entra ID.

The usual bridge has been an NPS server with the Azure MFA extension, which keeps a Windows Server in the authentication path. The cloud alternative is a RADIUS service that takes identity from Entra ID directly, paired with certificates delivered through Intune. That is the pattern Purple runs.

How it works with Purple

  1. Connect your Entra ID tenant

    Purple syncs users and groups from Entra ID, so WiFi access follows the directory you already manage.

  2. Point your SSIDs at Purple

    Set the SSID to WPA2 or WPA3-Enterprise and change its RADIUS server to Purple. The access points stay where they are.

  3. Put a certificate on every device

    Managed Windows, macOS, iOS and Android devices receive one through Intune over SCEP. Personal devices get one from the Purple app after the person signs in with Microsoft.

  4. Access follows the account

    Group membership can decide which VLAN a person lands on. Disable the account in Entra ID and the certificate stops authenticating.

What is supported

Identity source
Microsoft Entra ID, with users and groups synced to Purple.
Security and EAP methods
WPA2-Enterprise or WPA3-Enterprise with 802.1X. EAP-TLS for managed laptops, PEAP for legacy devices, iPSK for BYOD and IoT.
Managed devices
Microsoft Intune over SCEP, covering Windows, macOS, iOS and Android. Around 5 to 10 minutes of setup, once, for the whole organisation.
Personal devices
The Purple app, native on Windows, macOS, Linux, iOS and Android, installs a certificate-based WiFi pass.
Network policy
Entra ID group membership can drive VLAN assignment, so teams land on their own segment.
Access points
Any enterprise access point that speaks RADIUS, including Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. You reconfigure the SSID, not the hardware.
Certification
Purple is ISO 27001 certified, and GDPR and CCPA compliant.

What Purple does not do

  • You cannot bring your own certificate authority. Purple’s RADIUS authenticates against Purple’s backend, so the certificate has to be one Purple issued.
  • Purple does not check whether a device is patched or encrypted. Posture checking stays with your MDM.
  • The directory sync runs roughly hourly, and revocation applies to the next authentication rather than cutting a live session.

Every statement above about what Purple does is taken from Staff WiFi and Certificate-based WiFi via MDM.

Entra ID and cloud RADIUS: questions

Can Microsoft Entra ID do RADIUS for WiFi?

Not on its own. Entra ID speaks SAML and OIDC, not the RADIUS protocol your access points use, so 802.1X WiFi needs a RADIUS service in between. Purple runs that service in the cloud. Staff sign in with their Entra ID account, receive a certificate-based WiFi pass, and connect over WPA2 or WPA3-Enterprise with no NPS server.

Can Purple replace Microsoft NPS for WiFi authentication?

Yes, for WiFi. Your access points send 802.1X requests to Purple’s cloud RADIUS instead of an NPS server, and identity comes from Entra ID rather than on-premises Active Directory. You change the RADIUS server on each SSID; the access points themselves stay as they are.

Do I need Microsoft Intune to use Purple with Entra ID?

No. Intune is the zero-touch route for company-managed devices. Without it, people install their WiFi pass through the Purple app by signing in with their Microsoft account, which is also the route for personal phones and tablets.

Which EAP methods can I use?

EAP-TLS for managed laptops, PEAP for legacy devices that cannot hold a certificate, and iPSK for BYOD and IoT devices such as printers and sensors. All run over WPA2-Enterprise or WPA3-Enterprise.

What happens when someone leaves?

Disable the account in Entra ID and their certificate stops authenticating. The directory sync runs roughly hourly and revocation applies to the next authentication, so for a managed device you would also lock or wipe it through Intune.

Zuletzt geprüft:

Speak to an expert

Tell us what you need and we'll be in touch.