Cloud RADIUS for Okta WiFi authentication
Staff sign in with their Okta account and get certificate-based WPA2 or WPA3-Enterprise WiFi. Purple runs the RADIUS service in the cloud and takes identity from Okta, so there is no RADIUS agent server to host and no password-only EAP method to settle for.
How do you use Okta for WiFi authentication?
You need a RADIUS service between your access points and Okta. Okta’s own RADIUS agent runs on a server you host and supports password-based EAP-TTLS, not certificate-based EAP-TLS. Purple runs cloud RADIUS that takes identity from Okta, so staff sign in once with their Okta account and connect with a certificate.
Why Okta needs a RADIUS layer
Okta is a cloud identity provider; WiFi access points speak RADIUS. Okta’s answer is the Okta RADIUS agent, a service you install on a Windows or Linux server that proxies each RADIUS request to the Okta cloud.
The agent relies on PAP for the primary check, so it supports EAP-TTLS with PAP and EAP-GTC. It does not support PEAP-MSCHAPv2, the Windows default, and it does not support EAP-TLS natively. Certificate-based WiFi against Okta needs a cloud RADIUS service that uses Okta as the identity provider. That is the pattern Purple runs.
How it works with Purple
Connect Okta
Purple syncs users and groups from Okta, so WiFi access follows the directory you already manage.
Point your SSIDs at Purple
Set the SSID to WPA2 or WPA3-Enterprise and change its RADIUS server to Purple. No agent server to install.
Put a certificate on every device
People sign in to the Purple app with their Okta account and install a WiFi pass. Managed devices can receive a certificate through an MDM such as Intune, Jamf Pro, JumpCloud or IRU.
Access follows the account
Okta group membership can decide which VLAN a person lands on. Deactivate the user in Okta and the certificate stops authenticating.
What is supported
- Identity source
- Okta, with users and groups synced to Purple.
- Security and EAP methods
- WPA2-Enterprise or WPA3-Enterprise with 802.1X. EAP-TLS for managed laptops, PEAP for legacy devices, iPSK for BYOD and IoT.
- Personal devices
- The Purple app, native on Windows, macOS, Linux, iOS and Android, installs a certificate-based WiFi pass.
- Managed devices
- Certificates through Microsoft Intune, JumpCloud, IRU or Jamf Pro over SCEP.
- Network policy
- Okta group membership can drive VLAN assignment, so teams land on their own segment.
- Access points
- Any enterprise access point that speaks RADIUS, including Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. You reconfigure the SSID, not the hardware.
- Certification
- Purple is ISO 27001 certified, and GDPR and CCPA compliant.
What Purple does not do
- You cannot bring your own certificate authority. Purple’s RADIUS authenticates against Purple’s backend, so the certificate has to be one Purple issued.
- Purple does not check whether a device is patched or encrypted. Posture checking stays with your MDM.
- The directory sync runs roughly hourly, and revocation applies to the next authentication rather than cutting a live session.
Every statement above about what Purple does is taken from Staff WiFi and Certificate-based WiFi via MDM.
Guides for Okta WiFi authentication
The technical detail behind this page, including the routes that do not involve Purple.
Okta and RADIUS: extending your identity provider to WiFi authentication
The agent’s proxy model, MFA on WiFi and VLAN attribute mapping.
What is cloud RADIUS?
How RADIUS as a service works and when it replaces an on-site server.
How to set up a RADIUS server for WiFi authentication
The step-by-step 802.1X build, if you are weighing up running your own.
Enterprise WiFi security guide
802.1X, WPA3-Enterprise and certificate-based authentication, from first principles.
Other identity providers and device management
The same cloud RADIUS sits behind each of these. See the RADIUS-as-a-Service overview for the authentication flow, or compare cloud RADIUS providers.
Okta and cloud RADIUS: questions
How do you use Okta for WiFi authentication?
You need a RADIUS service between your access points and Okta. Okta’s own RADIUS agent runs on a server you host and supports password-based EAP-TTLS, not certificate-based EAP-TLS. Purple runs cloud RADIUS that takes identity from Okta, so staff sign in once with their Okta account and connect with a certificate.
Do I need the Okta RADIUS agent?
Not for WiFi that authenticates through Purple. Purple runs the RADIUS service and takes identity from Okta, so there is no agent server to install, patch or keep available.
Can I use EAP-TLS certificates with Okta?
Yes, through Purple. The Okta RADIUS agent does not support EAP-TLS natively, which is why certificate-based WiFi against Okta needs a separate RADIUS service. Purple issues the certificate and authenticates it against its cloud RADIUS, with Okta as the identity source.
Why does PEAP fail with the Okta RADIUS agent?
The agent does not support PEAP-MSCHAPv2, the default 802.1X method on Windows. Moving to the agent means reconfiguring clients for EAP-TTLS with PAP. Moving to certificates avoids the password exchange altogether.
What happens when someone leaves?
Deactivate the user in Okta and their certificate stops authenticating. The directory sync runs roughly hourly and revocation applies to the next authentication rather than cutting a live session.
最後審閱:
See Okta WiFi running on your own access points
Tell us your identity provider, device management and access point vendors, and we will show you the setup on a test tenant.
Speak to an expert
Tell us what you need and we'll be in touch.