Zum Hauptinhalt springen

Can Google Workspace authenticate WiFi users?

Not directly. Google Workspace has no RADIUS interface, so 802.1X WiFi needs a RADIUS service in between. The self-built route is a RADIUS server querying Google Secure LDAP, which needs a higher-tier licence. Purple runs cloud RADIUS that takes identity from Google Workspace, so staff sign in with their Google account and connect with a certificate.

Why Google Workspace needs a RADIUS layer

Unlike Active Directory, Google Workspace does not speak RADIUS and does not offer a network policy server. WiFi authentication against it always needs an intermediary.

The common self-built pattern is a RADIUS server such as FreeRADIUS querying Google Secure LDAP over ldap.google.com. Secure LDAP is only available on Enterprise and Cloud Identity Premium licences, and you still run the RADIUS server. The cloud alternative is a RADIUS service that takes identity from Google directly. That is the pattern Purple runs.

How it works with Purple

  1. Connect Google Workspace

    Purple syncs users and groups from Google Workspace, so WiFi access follows the directory you already manage.

  2. Point your SSIDs at Purple

    Set the SSID to WPA2 or WPA3-Enterprise and change its RADIUS server to Purple. No LDAP client to configure.

  3. Put a certificate on every device

    People sign in to the Purple app with their Google account and install a WiFi pass. Managed devices can receive a certificate through an MDM such as Intune, Jamf Pro, JumpCloud or IRU.

  4. Access follows the account

    Group membership can decide which VLAN a person lands on. Suspend the user in Google Workspace and the certificate stops authenticating.

What is supported

Identity source
Google Workspace, with users and groups synced to Purple.
Security and EAP methods
WPA2-Enterprise or WPA3-Enterprise with 802.1X. EAP-TLS for managed laptops, PEAP for legacy devices, iPSK for BYOD and IoT.
Personal devices
The Purple app, native on Windows, macOS, Linux, iOS and Android, installs a certificate-based WiFi pass.
Managed devices
Certificates through Microsoft Intune, JumpCloud, IRU or Jamf Pro over SCEP.
Network policy
Group membership can drive VLAN assignment, so teams land on their own segment.
Access points
Any enterprise access point that speaks RADIUS, including Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. You reconfigure the SSID, not the hardware.
Certification
Purple is ISO 27001 certified, and GDPR and CCPA compliant.

What Purple does not do

  • The Purple app is native on Windows, macOS, Linux, iOS and Android. ChromeOS is not on that list, and Google Admin Console is not one of the device management systems Purple provisions through. If your estate is mostly managed Chromebooks, speak to us before you plan the rollout.
  • You cannot bring your own certificate authority. Purple’s RADIUS authenticates against Purple’s backend, so the certificate has to be one Purple issued.
  • The directory sync runs roughly hourly, and revocation applies to the next authentication rather than cutting a live session.

Every statement above about what Purple does is taken from Staff WiFi and Certificate-based WiFi via MDM.

Google Workspace and cloud RADIUS: questions

Can Google Workspace authenticate WiFi users?

Not directly. Google Workspace has no RADIUS interface, so 802.1X WiFi needs a RADIUS service in between. The self-built route is a RADIUS server querying Google Secure LDAP, which needs a higher-tier licence. Purple runs cloud RADIUS that takes identity from Google Workspace, so staff sign in with their Google account and connect with a certificate.

Do I need Google Secure LDAP to use Purple?

No. Secure LDAP is how a RADIUS server you run yourself checks passwords against Google. Purple runs the RADIUS service and takes identity from Google Workspace, so there is no LDAP client or certificate to set up in the Admin Console for WiFi.

Does Purple work with Chromebooks?

The Purple app is native on Windows, macOS, Linux, iOS and Android, and ChromeOS is not on that list. If Chromebooks make up most of your estate, speak to us about your devices first. Our Google Workspace guide covers the Admin Console route for Chromebook 802.1X.

Which EAP methods can I use?

EAP-TLS for managed laptops, PEAP for legacy devices that cannot hold a certificate, and iPSK for BYOD and IoT devices such as printers and sensors. All run over WPA2-Enterprise or WPA3-Enterprise.

What happens when someone leaves?

Suspend the user in Google Workspace and their certificate stops authenticating. The directory sync runs roughly hourly and revocation applies to the next authentication rather than cutting a live session.

Zuletzt geprüft:

Speak to an expert

Tell us what you need and we'll be in touch.