Skip to main content

What is 802.1X?

Definition

802.1X is an IEEE standard for port-based network access control. On WiFi, it holds each user or device at the door until a RADIUS server has checked its credentials, carried inside the Extensible Authentication Protocol (EAP). It is the foundation of WPA2-Enterprise and WPA3-Enterprise.

802.1X explained

802.1X has three roles. The supplicant is the client device. The authenticator is the access point or switch, which blocks all traffic except authentication messages. The authentication server is RADIUS, which validates the credential against an identity store such as Active Directory, Microsoft Entra ID or Okta and returns Access-Accept or Access-Reject.

The credential depends on the EAP method. EAP-TLS uses certificates on both sides and removes passwords entirely. PEAP wraps a username and password inside a TLS tunnel. The choice sets how much PKI you run and how exposed you are to credential theft.

The value of 802.1X is individual accountability. Every session is tied to a named user or device, and when a staff member’s account is disabled in the directory, their WiFi access goes with it. A shared pre-shared key (PSK) cannot do that: one leaked password means changing it on every device. That is why 802.1X is the default for staff and corporate networks, while open or captive-portal access stays on the guest side.

Need more than a definition?

Talk to our team about how Purple combines guest WiFi, captive portals, RADIUS, and analytics into a single platform that runs on the access points you already own.