मुख्य सामग्री पर जाएं

How do you use Okta for WiFi authentication?

You need a RADIUS service between your access points and Okta. Okta’s own RADIUS agent runs on a server you host and supports password-based EAP-TTLS, not certificate-based EAP-TLS. Purple runs cloud RADIUS that takes identity from Okta, so staff sign in once with their Okta account and connect with a certificate.

Why Okta needs a RADIUS layer

Okta is a cloud identity provider; WiFi access points speak RADIUS. Okta’s answer is the Okta RADIUS agent, a service you install on a Windows or Linux server that proxies each RADIUS request to the Okta cloud.

The agent relies on PAP for the primary check, so it supports EAP-TTLS with PAP and EAP-GTC. It does not support PEAP-MSCHAPv2, the Windows default, and it does not support EAP-TLS natively. Certificate-based WiFi against Okta needs a cloud RADIUS service that uses Okta as the identity provider. That is the pattern Purple runs.

How it works with Purple

  1. Connect Okta

    Purple syncs users and groups from Okta, so WiFi access follows the directory you already manage.

  2. Point your SSIDs at Purple

    Set the SSID to WPA2 or WPA3-Enterprise and change its RADIUS server to Purple. No agent server to install.

  3. Put a certificate on every device

    People sign in to the Purple app with their Okta account and install a WiFi pass. Managed devices can receive a certificate through an MDM such as Intune, Jamf Pro, JumpCloud or IRU.

  4. Access follows the account

    Okta group membership can decide which VLAN a person lands on. Deactivate the user in Okta and the certificate stops authenticating.

What is supported

Identity source
Okta, with users and groups synced to Purple.
Security and EAP methods
WPA2-Enterprise or WPA3-Enterprise with 802.1X. EAP-TLS for managed laptops, PEAP for legacy devices, iPSK for BYOD and IoT.
Personal devices
The Purple app, native on Windows, macOS, Linux, iOS and Android, installs a certificate-based WiFi pass.
Managed devices
Certificates through Microsoft Intune, JumpCloud, IRU or Jamf Pro over SCEP.
Network policy
Okta group membership can drive VLAN assignment, so teams land on their own segment.
Access points
Any enterprise access point that speaks RADIUS, including Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. You reconfigure the SSID, not the hardware.
Certification
Purple is ISO 27001 certified, and GDPR and CCPA compliant.

What Purple does not do

  • You cannot bring your own certificate authority. Purple’s RADIUS authenticates against Purple’s backend, so the certificate has to be one Purple issued.
  • Purple does not check whether a device is patched or encrypted. Posture checking stays with your MDM.
  • The directory sync runs roughly hourly, and revocation applies to the next authentication rather than cutting a live session.

Every statement above about what Purple does is taken from Staff WiFi and Certificate-based WiFi via MDM.

Okta and cloud RADIUS: questions

How do you use Okta for WiFi authentication?

You need a RADIUS service between your access points and Okta. Okta’s own RADIUS agent runs on a server you host and supports password-based EAP-TTLS, not certificate-based EAP-TLS. Purple runs cloud RADIUS that takes identity from Okta, so staff sign in once with their Okta account and connect with a certificate.

Do I need the Okta RADIUS agent?

Not for WiFi that authenticates through Purple. Purple runs the RADIUS service and takes identity from Okta, so there is no agent server to install, patch or keep available.

Can I use EAP-TLS certificates with Okta?

Yes, through Purple. The Okta RADIUS agent does not support EAP-TLS natively, which is why certificate-based WiFi against Okta needs a separate RADIUS service. Purple issues the certificate and authenticates it against its cloud RADIUS, with Okta as the identity source.

Why does PEAP fail with the Okta RADIUS agent?

The agent does not support PEAP-MSCHAPv2, the default 802.1X method on Windows. Moving to the agent means reconfiguring clients for EAP-TTLS with PAP. Moving to certificates avoids the password exchange altogether.

What happens when someone leaves?

Deactivate the user in Okta and their certificate stops authenticating. The directory sync runs roughly hourly and revocation applies to the next authentication rather than cutting a live session.

अंतिम समीक्षा:

Speak to an expert

Tell us what you need and we'll be in touch.