Cloud RADIUS for Google Workspace WiFi authentication
Staff sign in with their Google Workspace account and get certificate-based WPA2 or WPA3-Enterprise WiFi. Purple runs the RADIUS service in the cloud and takes identity from Google, so you do not need Secure LDAP or a RADIUS server of your own.
Can Google Workspace authenticate WiFi users?
Not directly. Google Workspace has no RADIUS interface, so 802.1X WiFi needs a RADIUS service in between. The self-built route is a RADIUS server querying Google Secure LDAP, which needs a higher-tier licence. Purple runs cloud RADIUS that takes identity from Google Workspace, so staff sign in with their Google account and connect with a certificate.
Why Google Workspace needs a RADIUS layer
Unlike Active Directory, Google Workspace does not speak RADIUS and does not offer a network policy server. WiFi authentication against it always needs an intermediary.
The common self-built pattern is a RADIUS server such as FreeRADIUS querying Google Secure LDAP over ldap.google.com. Secure LDAP is only available on Enterprise and Cloud Identity Premium licences, and you still run the RADIUS server. The cloud alternative is a RADIUS service that takes identity from Google directly. That is the pattern Purple runs.
How it works with Purple
Connect Google Workspace
Purple syncs users and groups from Google Workspace, so WiFi access follows the directory you already manage.
Point your SSIDs at Purple
Set the SSID to WPA2 or WPA3-Enterprise and change its RADIUS server to Purple. No LDAP client to configure.
Put a certificate on every device
People sign in to the Purple app with their Google account and install a WiFi pass. Managed devices can receive a certificate through an MDM such as Intune, Jamf Pro, JumpCloud or IRU.
Access follows the account
Group membership can decide which VLAN a person lands on. Suspend the user in Google Workspace and the certificate stops authenticating.
What is supported
- Identity source
- Google Workspace, with users and groups synced to Purple.
- Security and EAP methods
- WPA2-Enterprise or WPA3-Enterprise with 802.1X. EAP-TLS for managed laptops, PEAP for legacy devices, iPSK for BYOD and IoT.
- Personal devices
- The Purple app, native on Windows, macOS, Linux, iOS and Android, installs a certificate-based WiFi pass.
- Managed devices
- Certificates through Microsoft Intune, JumpCloud, IRU or Jamf Pro over SCEP.
- Network policy
- Group membership can drive VLAN assignment, so teams land on their own segment.
- Access points
- Any enterprise access point that speaks RADIUS, including Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. You reconfigure the SSID, not the hardware.
- Certification
- Purple is ISO 27001 certified, and GDPR and CCPA compliant.
What Purple does not do
- The Purple app is native on Windows, macOS, Linux, iOS and Android. ChromeOS is not on that list, and Google Admin Console is not one of the device management systems Purple provisions through. If your estate is mostly managed Chromebooks, speak to us before you plan the rollout.
- You cannot bring your own certificate authority. Purple’s RADIUS authenticates against Purple’s backend, so the certificate has to be one Purple issued.
- The directory sync runs roughly hourly, and revocation applies to the next authentication rather than cutting a live session.
Every statement above about what Purple does is taken from Staff WiFi and Certificate-based WiFi via MDM.
Guides for Google Workspace WiFi authentication
The technical detail behind this page, including the routes that do not involve Purple.
Google Workspace WiFi authentication: Chromebook and LDAP integration
Secure LDAP, Admin Console WiFi profiles and Chromebook EAP support.
What is cloud RADIUS?
How RADIUS as a service works and when it replaces an on-site server.
How to set up a RADIUS server for WiFi authentication
The step-by-step 802.1X build, if you are weighing up running your own.
Enterprise WiFi security guide
802.1X, WPA3-Enterprise and certificate-based authentication, from first principles.
Other identity providers and device management
The same cloud RADIUS sits behind each of these. See the RADIUS-as-a-Service overview for the authentication flow, or compare cloud RADIUS providers.
Google Workspace and cloud RADIUS: questions
Can Google Workspace authenticate WiFi users?
Not directly. Google Workspace has no RADIUS interface, so 802.1X WiFi needs a RADIUS service in between. The self-built route is a RADIUS server querying Google Secure LDAP, which needs a higher-tier licence. Purple runs cloud RADIUS that takes identity from Google Workspace, so staff sign in with their Google account and connect with a certificate.
Do I need Google Secure LDAP to use Purple?
No. Secure LDAP is how a RADIUS server you run yourself checks passwords against Google. Purple runs the RADIUS service and takes identity from Google Workspace, so there is no LDAP client or certificate to set up in the Admin Console for WiFi.
Does Purple work with Chromebooks?
The Purple app is native on Windows, macOS, Linux, iOS and Android, and ChromeOS is not on that list. If Chromebooks make up most of your estate, speak to us about your devices first. Our Google Workspace guide covers the Admin Console route for Chromebook 802.1X.
Which EAP methods can I use?
EAP-TLS for managed laptops, PEAP for legacy devices that cannot hold a certificate, and iPSK for BYOD and IoT devices such as printers and sensors. All run over WPA2-Enterprise or WPA3-Enterprise.
What happens when someone leaves?
Suspend the user in Google Workspace and their certificate stops authenticating. The directory sync runs roughly hourly and revocation applies to the next authentication rather than cutting a live session.
Última revisão:
See Google Workspace WiFi running on your own access points
Tell us your identity provider, device management and access point vendors, and we will show you the setup on a test tenant.
Speak to an expert
Tell us what you need and we'll be in touch.