Cloud RADIUS for Microsoft Entra ID, without an NPS server
Staff sign in with the Entra ID account they already have and their devices join WPA2 or WPA3-Enterprise WiFi with a certificate. Purple runs the RADIUS service in the cloud, so there is no Network Policy Server to build, patch or keep in step with your directory.
Can Microsoft Entra ID do RADIUS for WiFi?
Not on its own. Entra ID speaks SAML and OIDC, not the RADIUS protocol your access points use, so 802.1X WiFi needs a RADIUS service in between. Purple runs that service in the cloud. Staff sign in with their Entra ID account, receive a certificate-based WiFi pass, and connect over WPA2 or WPA3-Enterprise with no NPS server.
Why Entra ID needs a RADIUS layer
Enterprise WiFi authenticates with 802.1X: the access point wraps the device’s credentials in a RADIUS request and waits for a yes or no. Microsoft Entra ID does not listen for RADIUS or LDAP, and it does not hold reversible NTLM password hashes for cloud-only accounts. The PEAP-MSCHAPv2 pattern that on-premises Active Directory and Windows Server NPS supported for years has nothing to check against once identity lives in Entra ID.
The usual bridge has been an NPS server with the Azure MFA extension, which keeps a Windows Server in the authentication path. The cloud alternative is a RADIUS service that takes identity from Entra ID directly, paired with certificates delivered through Intune. That is the pattern Purple runs.
How it works with Purple
Connect your Entra ID tenant
Purple syncs users and groups from Entra ID, so WiFi access follows the directory you already manage.
Point your SSIDs at Purple
Set the SSID to WPA2 or WPA3-Enterprise and change its RADIUS server to Purple. The access points stay where they are.
Put a certificate on every device
Managed Windows, macOS, iOS and Android devices receive one through Intune over SCEP. Personal devices get one from the Purple app after the person signs in with Microsoft.
Access follows the account
Group membership can decide which VLAN a person lands on. Disable the account in Entra ID and the certificate stops authenticating.
What is supported
- Identity source
- Microsoft Entra ID, with users and groups synced to Purple.
- Security and EAP methods
- WPA2-Enterprise or WPA3-Enterprise with 802.1X. EAP-TLS for managed laptops, PEAP for legacy devices, iPSK for BYOD and IoT.
- Managed devices
- Microsoft Intune over SCEP, covering Windows, macOS, iOS and Android. Around 5 to 10 minutes of setup, once, for the whole organisation.
- Personal devices
- The Purple app, native on Windows, macOS, Linux, iOS and Android, installs a certificate-based WiFi pass.
- Network policy
- Entra ID group membership can drive VLAN assignment, so teams land on their own segment.
- Access points
- Any enterprise access point that speaks RADIUS, including Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. You reconfigure the SSID, not the hardware.
- Certification
- Purple is ISO 27001 certified, and GDPR and CCPA compliant.
What Purple does not do
- You cannot bring your own certificate authority. Purple’s RADIUS authenticates against Purple’s backend, so the certificate has to be one Purple issued.
- Purple does not check whether a device is patched or encrypted. Posture checking stays with your MDM.
- The directory sync runs roughly hourly, and revocation applies to the next authentication rather than cutting a live session.
Every statement above about what Purple does is taken from Staff WiFi and Certificate-based WiFi via MDM.
Guides for Entra ID WiFi authentication
The technical detail behind this page, including the routes that do not involve Purple.
How to set up Azure Entra ID for WiFi authentication
The four-step EAP-TLS build: PKI, RADIUS, Intune profiles, controller.
Microsoft Entra ID WiFi authentication: enterprise integration guide
The three architecture patterns compared, including hybrid NPS.
How to use Microsoft Intune to push WiFi certificates to devices
What is cloud RADIUS?
How RADIUS as a service works and when it replaces an on-site server.
Enterprise WiFi security guide
802.1X, WPA3-Enterprise and certificate-based authentication, from first principles.
Other identity providers and device management
The same cloud RADIUS sits behind each of these. See the RADIUS-as-a-Service overview for the authentication flow, or compare cloud RADIUS providers.
Entra ID and cloud RADIUS: questions
Can Microsoft Entra ID do RADIUS for WiFi?
Not on its own. Entra ID speaks SAML and OIDC, not the RADIUS protocol your access points use, so 802.1X WiFi needs a RADIUS service in between. Purple runs that service in the cloud. Staff sign in with their Entra ID account, receive a certificate-based WiFi pass, and connect over WPA2 or WPA3-Enterprise with no NPS server.
Can Purple replace Microsoft NPS for WiFi authentication?
Yes, for WiFi. Your access points send 802.1X requests to Purple’s cloud RADIUS instead of an NPS server, and identity comes from Entra ID rather than on-premises Active Directory. You change the RADIUS server on each SSID; the access points themselves stay as they are.
Do I need Microsoft Intune to use Purple with Entra ID?
No. Intune is the zero-touch route for company-managed devices. Without it, people install their WiFi pass through the Purple app by signing in with their Microsoft account, which is also the route for personal phones and tablets.
Which EAP methods can I use?
EAP-TLS for managed laptops, PEAP for legacy devices that cannot hold a certificate, and iPSK for BYOD and IoT devices such as printers and sensors. All run over WPA2-Enterprise or WPA3-Enterprise.
What happens when someone leaves?
Disable the account in Entra ID and their certificate stops authenticating. The directory sync runs roughly hourly and revocation applies to the next authentication, so for a managed device you would also lock or wipe it through Intune.
अंतिम समीक्षा:
See Entra ID WiFi running on your own access points
Tell us your identity provider, device management and access point vendors, and we will show you the setup on a test tenant.
Speak to an expert
Tell us what you need and we'll be in touch.