- Home
- WiFi Glossary
- 802.1X
What is 802.1X?
Definition
802.1X is an IEEE standard for port-based network access control. On WiFi, it holds each user or device at the door until a RADIUS server has checked its credentials, carried inside the Extensible Authentication Protocol (EAP). It is the foundation of WPA2-Enterprise and WPA3-Enterprise.
802.1X explained
802.1X has three roles. The supplicant is the client device. The authenticator is the access point or switch, which blocks all traffic except authentication messages. The authentication server is RADIUS, which validates the credential against an identity store such as Active Directory, Microsoft Entra ID or Okta and returns Access-Accept or Access-Reject.
The credential depends on the EAP method. EAP-TLS uses certificates on both sides and removes passwords entirely. PEAP wraps a username and password inside a TLS tunnel. The choice sets how much PKI you run and how exposed you are to credential theft.
The value of 802.1X is individual accountability. Every session is tied to a named user or device, and when a staff member’s account is disabled in the directory, their WiFi access goes with it. A shared pre-shared key (PSK) cannot do that: one leaked password means changing it on every device. That is why 802.1X is the default for staff and corporate networks, while open or captive-portal access stays on the guest side.
Guides on 802.1X
- Technical guide802.1X vs PSK vs open WiFi: which authentication method is right for you?
- Technical guideHow to configure 802.1X WiFi authentication
- Technical guideTroubleshooting 802.1X authentication failures
Where it fits
- Pillar guideEnterprise WiFi security guide
- Purple productWPA-Enterprise with Purple
- Free toolRADIUS setup guide
Related terms
Need more than a definition?
Talk to our team about how Purple combines guest WiFi, captive portals, RADIUS, and analytics into a single platform that runs on the access points you already own.