- Purple
- Enterprise WiFi security and authentication: a complete guide
- Portnox Alternatives: Cloud RADIUS Without the Full NAC
Portnox Alternatives: Cloud RADIUS Without the Full NAC
You will be able to decide whether your estate needs full NAC or only cloud RADIUS for WiFi, using a three-question test. You can then compare Portnox, Purple, SecureW2 and JumpCloud on wired enforcement, posture checks, certificates, guest access and three-year running cost, and plan a site-by-site pilot.
Video overview
Part of our core series: Enterprise WiFi Security Guide →
- Do you need full NAC or just cloud RADIUS for WiFi?
- What cloud RADIUS does
- What NAC adds on top
- The three-question test
- Where Portnox, Purple, SecureW2 and JumpCloud genuinely differ
- When is Portnox the right call?
- Where Portnox excels
- Where Portnox overreaches for venue WiFi
- Worked scenario: a regional council
- When is cloud RADIUS without the NAC the right call?
- Purple: guest and staff WiFi on one platform
- SecureW2: certificate-first authentication
- JumpCloud: RADIUS as part of the directory
- Worked scenario: a 30-hotel group
- What about wired NAC needs?
- Option 1: segment the wired estate at the switch
- Option 2: wired 802.1X with cloud RADIUS
- Option 3: NAC for wired, cloud RADIUS for WiFi
- Option 4: full NAC everywhere
- What does each option cost to run?
- Questions to put to every vendor
- Where hidden costs hide
- How to decide for your estate
- Worked scenario: a 120-store retail chain
- A sensible order of work
- Frequently asked questions
- Is Purple a direct replacement for Portnox?
- Can I run cloud RADIUS for WiFi and keep a NAC for wired ports?
- Does Purple work with the access points I already own?
- How do I migrate staff WiFi from Portnox to cloud RADIUS?
- Is cloud RADIUS without NAC enough for PCI DSS?
- Is SecureW2 or JumpCloud cheaper than Portnox?
- Does cloud RADIUS handle leavers automatically?
- Is Purple compliant with GDPR?
For organizations seeking Portnox alternatives to secure WiFi without full network access control, cloud RADIUS using the IEEE 802.1X standard is the answer. Platforms like Purple integrate with Microsoft Entra ID to authenticate users across more than 80,000 venues, eliminating complex posture checks while maintaining secure staff and guest access.
Do you need full NAC or just cloud RADIUS for WiFi?
Start with the job, not the vendor. Two layers get bundled together in sales conversations, and they solve different problems.
What cloud RADIUS does
RADIUS, defined in IETF RFC 2865, is the protocol your access points use to ask whether a device may join. IEEE 802.1X is the port-based access control standard that carries that request. It runs between the device, the access point or switch, and the RADIUS server. Cloud RADIUS hosts that server as a service, so you run no appliance on site.
A cloud RADIUS service checks an identity against your directory and returns a decision. It can also return a VLAN, a separate logical network segment, so staff, guests and devices stay isolated. That covers most WiFi authentication needs.
What NAC adds on top
A NAC platform does more than say yes or no. It discovers devices across wired, wireless and VPN connections. It assesses posture, meaning whether a device meets your security baseline before it connects. It then quarantines or remediates devices that fail. Portnox Cloud bundles this with its own cloud RADIUS service, according to Portnox's product documentation.
The three-question test
Three questions separate the two requirements:
- Must you stop unknown devices plugging into wired switch ports?
- Must you check a laptop's patch level, antivirus or disk encryption before it connects?
- Does an auditor or insurer require one access policy across wired, wireless and VPN?
If you answer no to all three, you need cloud RADIUS. If you answer yes to the first two, NAC earns its cost. If your wired estate is fixed tills, printers and access points in locked comms rooms, question one often answers itself.
Where Portnox, Purple, SecureW2 and JumpCloud genuinely differ
All four authenticate devices using 802.1X and RADIUS. The differences sit in what surrounds that core: wired enforcement, posture checks, certificates and guest access.
| Portnox | Purple | SecureW2 | JumpCloud | |
|---|---|---|---|---|
| Primary category | Cloud-native NAC with built-in cloud RADIUS | Guest and staff WiFi platform with cloud RADIUS | Cloud RADIUS and managed PKI | Directory and device management platform with cloud RADIUS |
| Wired 802.1X port control | Yes, a core feature | No, WiFi-focused | Yes, wired and wireless | Documented for WiFi and VPN |
| Endpoint posture checks | Yes, agent-based risk assessment | No | Policy lookups against identity provider and MDM | No dedicated posture engine |
| Guest captive portal and first-party data | Not a product focus | Yes, with conscious-choice opt-ins and WiFi analytics | Not a product focus | Not a product focus |
| Staff WiFi methods | 802.1X, MAC authentication bypass | 802.1X, iPSK, SecurePass | EAP-TLS certificates, PEAP | 802.1X against directory credentials or certificates |
| Identity providers | Microsoft Entra ID, Okta, Google Workspace | Microsoft Entra ID, Okta, Google Workspace | Microsoft Entra ID, Okta, Google Workspace | JumpCloud directory, synced from Microsoft Entra ID or Google Workspace |
| Hardware | Any 802.1X-capable switch or access point | Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme, Fortinet | Any 802.1X-capable switch or access point | Any 802.1X-capable access point |
| Best fit | Mixed wired and wireless estates with managed laptops | Venues running guest and staff WiFi together | IT teams standardising on certificates | Organisations already using JumpCloud as their directory |
A few terms need defining. EAP-TLS, specified in RFC 5216, authenticates a device with a digital certificate instead of a password. PEAP wraps a username and password exchange inside an encrypted tunnel. iPSK, or identity pre-shared key, gives each person or device its own WiFi key on a single network name. MAC authentication bypass, or MAB, admits devices that cannot run 802.1X based on their hardware address. Public key infrastructure, or PKI, is the system that issues and revokes those certificates.
When is Portnox the right call?
Portnox earns its place when access control must reach beyond WiFi. Its documentation covers wired, wireless and VPN access control and endpoint risk assessment. It also covers TACACS+, the protocol that controls administrator logins to switches and routers. If you need all of that from one console, a bundle makes sense.
Where Portnox excels
- Wired port enforcement. An unknown laptop plugged into a meeting room port gets blocked or quarantined.
- Posture before access. Managed laptops must pass health checks before reaching sensitive systems.
- One policy plane. Wired, wireless and VPN rules live in a single place, which simplifies audit evidence.
- Device administration. TACACS+ governs who can change switch and router configurations.
Healthcare and public-sector estates often fit this profile. Clinical and office networks mix managed laptops, wired desks and remote access. See how Purple approaches Healthcare venues, where patient and visitor WiFi still sits alongside clinical networks.
Where Portnox overreaches for venue WiFi
If your problem is WiFi onboarding, a NAC bundle brings costs you will not use. Posture agents need deploying and maintaining on every managed device. Wired enforcement needs switch configuration at every site. None of that improves the guest login at a hotel, store or stadium.
Portnox also does not position itself as a guest WiFi platform. If you need a captive portal, marketing consent and visit data, you will buy a second product. A captive portal is the web page a visitor sees before WiFi access is granted.
Worked scenario: a regional council
Situation. A council ran 12 office buildings and nine libraries. It had 600 wired desk ports, 1,100 managed laptops and a VPN for home working. Its insurer asked for evidence that unknown devices could not reach the corporate network.
What was done. The council deployed NAC across wired, wireless and VPN, with posture checks on managed laptops. Library visitor WiFi moved to a separate guest SSID on its own VLAN, outside NAC scope.
Outcome. Three separate access policies, for wired, wireless and VPN, became one. All 600 desk ports moved under enforcement. Visitor devices stayed out of the NAC licence count entirely. This modelled scenario shows the point: buy NAC where the wired and posture requirement exists, not for visitor WiFi.
When is cloud RADIUS without the NAC the right call?
Cloud RADIUS wins when WiFi is the estate you need to secure. You keep 802.1X and VLAN segmentation without agents, posture engines or wired rollout. The three alternatives suit different starting points.
Purple: guest and staff WiFi on one platform
Purple is a cloud overlay that layers on top of your existing infrastructure. It is hardware-agnostic, running on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. No rip and replace is required.
For staff, Purple's Identity-Based Networks authenticate against Microsoft Entra ID, Okta or Google Workspace. When HR disables a leaver in the directory, their WiFi access goes with it. That handles joiners, movers and leavers without rotating a shared password. SecurePass, Verify and Shield are security add-ons on top of the Connect, Capture and Engage plans.
For guests, Purple runs the captive portal, conscious-choice opt-ins and first-party data capture on the same platform. Captive portals have one known quirk. If a visitor misses the login prompt, an HTTPS page cannot be redirected cleanly, so the browser shows a certificate warning. Purple's support article "Connection Error" explains the cause and the workaround. OpenRoaming and Passpoint (also called Hotspot 2.0) remove the portal step by letting devices join securely and automatically.
Purple's scale is its own evidence. We have run since 2012 across 80,000+ live venues, with 440 million logins in 2024. Purple reports 99.999% uptime and holds ISO 27001, Cyber Essentials and B Corp certification. The platform is GDPR and CCPA compliant.
SecureW2: certificate-first authentication
SecureW2 combines cloud RADIUS with managed PKI, according to its product documentation. Its JoinNow onboarding client installs certificates on devices so they authenticate with EAP-TLS. That removes passwords from WiFi authentication altogether. It suits IT teams with managed device fleets who want certificates everywhere, including wired 802.1X, without full NAC.
JumpCloud: RADIUS as part of the directory
JumpCloud includes cloud RADIUS within its directory platform. Staff authenticate to WiFi with the same identity they use for everything else in JumpCloud. If JumpCloud already runs your directory, adding RADIUS involves no new vendor and no new identity source.
Worked scenario: a 30-hotel group
Situation. A hotel group ran Cisco Meraki access points across 30 hotels. Staff WiFi used one shared password per hotel. A Portnox quote covered 4,500 endpoints, including wired tills, printers and back-office PCs. The actual requirement was 1,800 staff devices joining WiFi, plus guest access.
What was done. The group kept wired tills on a segmented VLAN managed at the switch. Staff WiFi moved to identity-based 802.1X against Microsoft Entra ID. Guest WiFi moved to a captive portal with opt-in consent on the same platform.
Outcome. The licensed scope fell from 4,500 endpoints to the 1,800 staff devices that actually join WiFi. Thirty shared hotel passwords were retired, so a leaver no longer forces 30 password changes. Guest access and staff authentication now run from one console instead of two products. This is a modelled scenario, with outcomes calculated from its own inputs. Read more on Hotels.
Got questions about your specific setup?
Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.
What about wired NAC needs?
Wired requirements are the main reason teams look at Portnox. Before you buy a NAC to cover them, test whether you need posture or only authentication.
Option 1: segment the wired estate at the switch
Fixed devices such as tills, kitchen printers and access points rarely move. Put them on dedicated VLANs with switch-level port security. PCI DSS, published by the PCI Security Standards Council, treats network segmentation as a way to reduce cardholder data scope. Many retail and hospitality estates meet their wired requirement this way.
Option 2: wired 802.1X with cloud RADIUS
If you want wired authentication without posture checks, use a cloud RADIUS service that supports wired 802.1X. SecureW2 documents this. You get identity on every port without agents or a NAC licence. Devices that cannot run 802.1X fall back to MAB.
Option 3: NAC for wired, cloud RADIUS for WiFi
Some estates need posture on head-office desks but not at venues. You can scope NAC to head office and run venue WiFi on a separate cloud RADIUS platform. This split keeps the NAC licence count small. It also stops guest devices inflating your endpoint numbers.
Option 4: full NAC everywhere
Choose this when posture checks on wired, wireless and VPN are a hard requirement. Government networks handling sensitive data and clinical networks often land here. NIST SP 800-207, the US zero trust architecture guidance, describes continuous device assessment of the kind NAC provides.
What does each option cost to run?
Licence price is only one line. Agents, certificates, switch work and a second guest platform add cost over a three-year term. Compare these drivers before you compare quotes.
| Cost driver | Portnox | Purple | SecureW2 | JumpCloud |
|---|---|---|---|---|
| Licence model | Quote-based subscription | Connect, Capture or Engage plan, plus SecurePass, Verify or Shield add-ons | Quote-based subscription | Published per-person monthly packages |
| On-site appliance | None required | None required | None required | None required |
| Endpoint agent | Agent for posture checks | None | JoinNow client for certificate onboarding | JumpCloud agent if you use its device management |
| Certificates and PKI | Built-in certificate authority | Not required for iPSK | Managed PKI is the core product | Directory credentials, certificate option available |
| Separate guest WiFi platform | Required | Included | Required | Required |
| Wired rollout effort | Switch configuration at every site | None, WiFi only | Switch configuration where wired 802.1X is used | None for WiFi-only use |
Questions to put to every vendor
- Does the licence count wired, wireless and VPN endpoints together, or separately?
- Are guest and visitor devices counted towards the licence?
- Who deploys and maintains the endpoint agent, and on how many devices?
- What happens to authentication if the cloud service is unreachable?
- Which access point and switch vendors are tested and supported?
Where hidden costs hide
The biggest hidden cost is the second product. If your NAC or RADIUS vendor does not run guest WiFi, you buy and integrate a captive portal separately. You then manage two consoles, two contracts and two support routes. Guest WiFi also feeds visit data. If that matters, read Presence analytics vs engagement analytics.
The second hidden cost is agent maintenance. Every operating system update can break an agent. Factor support hours into your total cost of ownership, not only licence fees.
How to decide for your estate
Map your situation to a recommendation. The matrix below covers the patterns IT and venue operations teams raise most when evaluating Portnox alternatives.
| Your situation | Recommendation | Why |
|---|---|---|
| Wired desks, managed laptops, posture required by auditor | Portnox | Posture and wired enforcement are the requirement |
| Hotels, stores or venues needing guest and staff WiFi | Purple | One platform for captive portal and identity-based staff WiFi |
| Managed fleet, certificates wanted on wired and wireless | SecureW2 | Managed PKI with EAP-TLS, no posture engine |
| JumpCloud already your directory, WiFi-only need | JumpCloud | RADIUS from the identity source you already run |
| Head office needs posture, venues need WiFi | Portnox at head office, Purple at venues | NAC scoped to where posture matters |
| Fixed wired devices only, card payments in scope | Switch VLAN segmentation plus cloud RADIUS for WiFi | Segmentation reduces PCI DSS scope without NAC |
Worked scenario: a 120-store retail chain
Situation. A retailer ran 120 stores, each with staff handhelds and phones on WiFi. Tills were wired on a separate network. The IT team already used JumpCloud as its directory and was evaluating Portnox for staff WiFi.
What was done. The team applied the three-question test. Wired tills were already segmented, posture checks were not required, and no auditor asked for a unified policy. Staff WiFi moved to 802.1X against the existing directory. Shopper WiFi ran separately with its own captive portal.
Outcome. The team avoided rolling a posture agent to 1,400 handhelds and phones. It retired 120 shared store passwords. A leaver now loses WiFi access in every store when their directory account is disabled. This is a modelled scenario. See how Purple supports Retail estates.
A sensible order of work
- List every device type and whether it connects wired, wireless or both.
- Run the three-question test for each site type, not the estate as a whole.
- Price NAC only for the sites and devices that need posture.
- Price cloud RADIUS for everything else, including guest WiFi.
- Pilot one site, one SSID at a time, before you commit across the estate.
Transport follows the same logic. Rail operators including c2c Rail and Avanti West Coast run passenger WiFi on Purple, where onboard posture checks make no sense. See Trains.
Frequently asked questions
Is Purple a direct replacement for Portnox?
No, not for every Portnox use case. Purple replaces Portnox where your requirement is WiFi authentication for staff and guests. Purple does not offer wired port enforcement or endpoint posture checks. If you need those, keep a NAC for the wired and managed-laptop estate. Run Purple for venue WiFi, where it also provides the captive portal, conscious-choice opt-ins and WiFi analytics that Portnox does not position itself to deliver.
Can I run cloud RADIUS for WiFi and keep a NAC for wired ports?
Yes, and many estates should. Scope the NAC to sites and devices that need posture checks, such as head office desks and managed laptops. Run venue and guest WiFi on a separate cloud RADIUS platform. This keeps guest devices out of your NAC licence count. It also avoids deploying posture agents to handhelds and phones that never touch sensitive systems.
Does Purple work with the access points I already own?
Yes. Purple is hardware-agnostic and runs as a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. No rip and replace is required. You point your access points at Purple for authentication and the captive portal, and your existing wireless network keeps running underneath.
How do I migrate staff WiFi from Portnox to cloud RADIUS?
Migrate one SSID and one site at a time. Create the new staff network alongside the existing one, authenticated against Microsoft Entra ID, Okta or Google Workspace. Move a pilot group, confirm VLAN assignment and roaming, then expand. Leave wired enforcement on Portnox until you have decided whether wired posture is still a requirement. Retire the old SSID only once every device has moved.
Is cloud RADIUS without NAC enough for PCI DSS?
Yes, for many card-accepting venues, provided payment systems are segmented. PCI DSS treats network segmentation as a way to reduce the scope of cardholder data environments. Keep tills and payment devices on isolated wired VLANs. Run staff and guest WiFi on separate segments authenticated through cloud RADIUS. Confirm your segmentation design with your Qualified Security Assessor before you rely on it.
Is SecureW2 or JumpCloud cheaper than Portnox?
Usually yes for WiFi-only needs, because you avoid paying for unused NAC features. JumpCloud publishes per-person monthly packages with RADIUS in selected tiers. SecureW2 and Portnox quote per deal. Compare total cost, not licence price. Include agent maintenance, certificate management, switch configuration and a separate guest WiFi platform, which all three require and Purple includes.
Does cloud RADIUS handle leavers automatically?
Yes, when it authenticates against your identity provider. Purple's Identity-Based Networks check staff against Microsoft Entra ID, Okta or Google Workspace. When HR disables a leaver's account, their WiFi access ends with it. You no longer rotate a shared password across every site. This covers joiners, movers and leavers from one directory, instead of a separate WiFi account list.
Is Purple compliant with GDPR?
Yes. Purple is GDPR and CCPA compliant and certified to ISO 27001 and Cyber Essentials. Guest data capture uses conscious-choice opt-ins, so visitors decide what they share. Purple has operated since 2012 across 80,000+ live venues. That compliance posture applies to both guest WiFi data and staff authentication records held on the platform.
Key Definitions
RADIUS
Remote Authentication Dial In User Service, specified in IETF RFC 2865. It defines how a network access server, such as an access point or switch, sends an access request to a central server and receives an accept or reject decision, optionally with attributes such as a VLAN assignment.
Every option in this guide authenticates devices through RADIUS. The decision is whether you host it as a cloud service on its own or buy it bundled inside a NAC platform.
IEEE 802.1X
The IEEE standard for port-based network access control. It carries authentication between the device, the access point or switch, and the RADIUS server, and keeps a port or wireless association closed until the server approves the identity.
Portnox, Purple, SecureW2 and JumpCloud all use 802.1X. The question is whether you need it on wired switch ports as well as WiFi, which drives switch configuration effort at every site.
Network access control (NAC)
A platform that adds device discovery across wired, wireless and VPN connections, posture assessment against a security baseline, and quarantine or remediation of failing devices, on top of 802.1X and RADIUS authentication.
You meet NAC when an auditor or insurer asks for one access policy across wired, wireless and VPN. It earns its cost where posture and wired enforcement are genuine requirements.
Posture assessment
A check, usually performed by an endpoint agent, that a device meets your security baseline, such as patch level, antivirus status or disk encryption, before it is admitted to the network.
Posture is the main capability that separates NAC from cloud RADIUS. If you do not need it, you avoid deploying and maintaining an agent on every managed device.
VLAN
A virtual LAN, defined in IEEE 802.1Q, which splits one physical network into separate logical segments. A RADIUS server can return a VLAN assignment so each authenticated device lands on the correct segment.
VLANs isolate staff, guests, tills and other devices. Segmenting payment devices on their own VLAN is how many venues reduce PCI DSS scope without NAC.
EAP-TLS
An Extensible Authentication Protocol method specified in IETF RFC 5216. The device and server authenticate each other with digital certificates inside a TLS handshake, removing passwords from WiFi authentication.
EAP-TLS is the core of SecureW2's certificate-first approach. Choose it when you run a managed fleet and want certificates on wired and wireless without full NAC.
PEAP
Protected EAP, an 802.1X authentication method that wraps a username and password exchange inside an encrypted TLS tunnel established with the server's certificate.
PEAP lets staff join WiFi with directory credentials instead of device certificates, which lowers onboarding effort where you have no PKI in place.
iPSK
Identity pre-shared key, a method that gives each person or device its own WiFi key on a single network name, with the RADIUS server mapping each key to an identity and VLAN.
Purple supports iPSK for staff WiFi without certificates. It replaces a shared password per site, so one leaver no longer forces a password change across every venue.
MAC authentication bypass (MAB)
A fallback that admits devices unable to run an 802.1X supplicant, such as printers, by checking their hardware MAC address against an allowed list on the RADIUS server.
MAB matters when you extend wired 802.1X to fixed devices. It is listed as a Portnox staff method and as the fallback for cloud RADIUS on wired ports.
Captive portal
The web page a visitor sees before WiFi access is granted, used for terms acceptance, login and consent capture. HTTPS pages cannot be redirected cleanly to it, which can trigger certificate warnings in the browser.
Portnox, SecureW2 and JumpCloud do not run guest WiFi, so you would buy a captive portal separately. Purple includes it with conscious-choice opt-ins and first-party data capture.
PCI DSS
The Payment Card Industry Data Security Standard, published by the PCI Security Standards Council. It treats network segmentation as a way to reduce the scope of the cardholder data environment.
Retail and hospitality estates often meet their wired requirement by isolating tills on dedicated VLANs. Confirm the segmentation design with your Qualified Security Assessor before relying on it.
NIST SP 800-207
The US National Institute of Standards and Technology special publication on zero trust architecture. It describes continuous assessment of devices and identities before and during access to resources.
Government networks handling sensitive data and clinical networks often cite zero trust guidance when they justify full NAC with posture checks everywhere.
Worked Examples
A regional council runs 12 office buildings and nine libraries, with 600 wired desk ports, 1,100 managed laptops and a VPN for home working. Its insurer wants evidence that unknown devices cannot reach the corporate network. What should it deploy?
The council deployed NAC across wired, wireless and VPN, with posture checks on managed laptops. Library visitor WiFi moved to a separate guest SSID on its own VLAN, outside NAC scope. Three separate access policies became one, and all 600 desk ports moved under enforcement. Visitor devices stayed out of the NAC licence count entirely. This modelled scenario shows where NAC belongs: the wired and posture requirement is real, so the cost is justified, while visitor WiFi gains nothing from it.
A hotel group runs Cisco Meraki access points across 30 hotels with one shared staff password per hotel. A Portnox quote covers 4,500 endpoints, but only 1,800 staff devices actually join WiFi, plus guest access. How should it scope the purchase?
The group kept wired tills on a segmented VLAN managed at the switch. Staff WiFi moved to identity-based 802.1X against Microsoft Entra ID, and guest WiFi moved to a captive portal with opt-in consent on the same platform. The licensed scope fell from 4,500 endpoints to the 1,800 staff devices that join WiFi. Thirty shared passwords were retired, so a leaver no longer forces 30 password changes. Guest and staff access now run from one console instead of two products. This is a modelled scenario.
A retailer with 120 stores already uses JumpCloud as its directory and is evaluating Portnox for staff handhelds and phones on WiFi. Tills are wired on a separate network. Does it need NAC?
The team applied the three-question test. Wired tills were already segmented, posture checks were not required, and no auditor asked for a unified policy. Staff WiFi moved to 802.1X against the existing directory, and shopper WiFi ran separately with its own captive portal. The team avoided rolling a posture agent to 1,400 handhelds and phones and retired 120 shared store passwords. A leaver now loses WiFi access in every store when their directory account is disabled. This is a modelled scenario.
Frequently asked questions
Is Purple a direct replacement for Portnox?
No, not for every Portnox use case. Purple replaces Portnox where your requirement is WiFi authentication for staff and guests. Purple does not offer wired port enforcement or endpoint posture checks. If you need those, keep a NAC for the wired and managed-laptop estate. Run Purple for venue WiFi, where it also provides the captive portal, conscious-choice opt-ins and WiFi analytics that Portnox does not position itself to deliver.
Can I run cloud RADIUS for WiFi and keep a NAC for wired ports?
Yes, and many estates should. Scope the NAC to sites and devices that need posture checks, such as head office desks and managed laptops. Run venue and guest WiFi on a separate cloud RADIUS platform. This keeps guest devices out of your NAC licence count. It also avoids deploying posture agents to handhelds and phones that never touch sensitive systems.
Does Purple work with the access points I already own?
Yes. Purple is hardware-agnostic and runs as a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. No rip and replace is required. You point your access points at Purple for authentication and the captive portal, and your existing wireless network keeps running underneath.
How do I migrate staff WiFi from Portnox to cloud RADIUS?
Migrate one SSID and one site at a time. Create the new staff network alongside the existing one, authenticated against Microsoft Entra ID, Okta or Google Workspace. Move a pilot group, confirm VLAN assignment and roaming, then expand. Leave wired enforcement on Portnox until you have decided whether wired posture is still a requirement. Retire the old SSID only once every device has moved.
Is cloud RADIUS without NAC enough for PCI DSS?
Yes, for many card-accepting venues, provided payment systems are segmented. PCI DSS treats network segmentation as a way to reduce the scope of cardholder data environments. Keep tills and payment devices on isolated wired VLANs. Run staff and guest WiFi on separate segments authenticated through cloud RADIUS. Confirm your segmentation design with your Qualified Security Assessor before you rely on it.
Is SecureW2 or JumpCloud cheaper than Portnox?
Usually yes for WiFi-only needs, because you avoid paying for unused NAC features. JumpCloud publishes per-person monthly packages with RADIUS in selected tiers. SecureW2 and Portnox quote per deal. Compare total cost, not licence price. Include agent maintenance, certificate management, switch configuration and a separate guest WiFi platform, which all three require and Purple includes.
Does cloud RADIUS handle leavers automatically?
Yes, when it authenticates against your identity provider. Purple's Identity-Based Networks check staff against Microsoft Entra ID, Okta or Google Workspace. When HR disables a leaver's account, their WiFi access ends with it. You no longer rotate a shared password across every site. This covers joiners, movers and leavers from one directory, instead of a separate WiFi account list.
Is Purple compliant with GDPR?
Yes. Purple is GDPR and CCPA compliant and certified to ISO 27001 and Cyber Essentials. Guest data capture uses conscious-choice opt-ins, so visitors decide what they share. Purple has operated since 2012 across 80,000+ live venues. That compliance posture applies to both guest WiFi data and staff authentication records held on the platform.
Continue reading in this series
iOS and macOS 802.1X troubleshooting: a deployment checklist for Intune, Jamf and Entra ID
Use this checklist to diagnose why iPhones, iPads and Macs fail 802.1X on Intune or Jamf Pro. Each failure maps to one of four causes: server trust, identity certificate, macOS mode or Entra ID group scoping. You will confirm the cause from eapolclient and RADIUS logs, apply the fix and stage future certificate rotations.
Intune WiFi profile server trust: certificate server names and root CA checklist for Entra ID
You will be able to configure the server validation half of an Intune WiFi profile so EAP-TLS and PEAP connect on Windows, Apple and Android. You will match certificate server names to the RADIUS certificate, deploy the correct root CA, align Entra ID group assignments, and stage certificate renewals before they silently break connections.
Android 802.1X and EAP-TLS troubleshooting: a deployment checklist for Intune and Entra ID
You will be able to pinpoint why managed Android phones fail EAP-TLS on your staff SSID and fix it in Intune. Match each symptom to the four usual causes - missing CA or domain, client certificate in the wrong profile, a mismatched RADIUS server names value, or an undelivered trusted root. Then apply a rollout checklist that stops repeat outages.
Got questions about your specific setup?
Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.