Skip to main content
Every EntryPoint Context is one of four variants, picked in the Create RADIUSaaS Context wizard. Each variant serves a distinct audience; most Organizations run more than one Context to cover all their audiences.
Variant dropdown in the Create RADIUSaaS Context wizard
The wizard offers three options (verbatim):
  • EntryPoint 2.0 (Dot1x PEAP, Entra) — hosts both EAP-PEAP and EAP-TLS Groups. In this documentation we describe the two method families as separate chapters — see EAP-PEAP and EAP-TLS with Microsoft Entra ID — because they serve different audiences.
  • EntryPoint 2.0 (Radius Proxy / eduroam) — see Radius Proxy.
  • EntryPoint 1.0 (IPSK) — see iPSK for Cisco Networks.

Side-by-side feature matrix

EAP-PEAPEAP-TLS + EntraiPSK for CiscoRadius Proxy
Wizard variantDot1x PEAP, EntraDot1x PEAP, EntraIPSKRadius Proxy / eduroam
Primary audienceAny audience with a username+password identity — employees, contractor firms, vendor teams, event cohorts, studentsEmployees on MDM-enrolled devicesIoT fleets on Cisco Wi-Fieduroam visitors; roaming partners
CredentialUsername + password (auto-generated)User or device certificatePer-Group shared PSKUpstream decides
Identity sourceLocal PEAP store or Microsoft Entra IDMicrosoft Entra ID (operationally required)Device MAC → GroupRemote RADIUS server
Groups per ContextMany (one per audience)Many (one per Entra group)Many (one per device class)Exactly one (Default Device Group)
Group-to-Entra-group mappingOptional (for Entra-backed PEAP)Required
Self-Service portalYes (per-user Personal PEAP Account + per-OS setup guides)NoYes (Group admin + PSK admin + device admin)No
MAB fallbackInside Device-Cert Groups (shared with EAP-TLS)Inside Device-Cert Groups— (MAB sent by WLAN becomes iPSK)
Device Compliance Check (Intune)
Bulk device import✓ (CSV)
Typical VLAN strategyOne VLAN per audience (or shared across similar audiences)One VLAN per roleOne VLAN per device classOne VLAN for visitors
Typical Group namesCorporate Staff, Acme Consulting, HVAC Contractors, Summer Interns 2026Corporate Staff, Finance, Managed Laptops, Reception KiosksRobot Cleaners, Digital Signage, Smart Locks, Lab SensorsDefault Device Group

Picking per audience

  • Corporate staff with MDM-enrolled devices → EAP-TLS with Microsoft Entra ID. Cert-based auth, Entra group mapping, Intune posture.
  • Anyone on a password identity you want delegated admin for → EAP-PEAP. Employees via Entra group mapping; contractor firms, vendor teams, event cohorts and flex-workforce pools via local Personal PEAP Accounts. One Group per audience, one lead per Group, each audience runs itself.
  • Printers, VoIP phones, sensors, other non-802.1X gear behind the same VLAN as managed devices → MAB inside a Device-Cert Group (part of the EAP-TLS variant).
  • IoT on Cisco Wi-Fi, owned by different internal / vendor teams → iPSK. One Group per device class, distributed administration via Self-Service.
  • Visiting researchers / eduroam federation → Radius Proxy. Forward to the federation; no local identities.
  • Short-stay visitors on a captive portal → not EntryPoint. See Sign In.
  • Shared-SSID, per-unit key on Meraki (residential, co-living) → not EntryPoint. See EasyPSK for Cisco Networks.

Combining on one Context

A single EntryPoint 2.0 (Dot1x PEAP, Entra) Context can host EAP-PEAP and EAP-TLS Groups together — two independent master toggles on Client Authentication Methods. See Combining with EAP-TLS & MAB and Combining with EAP-PEAP. Variants of different wizard types (Dot1x, iPSK, Radius Proxy) are separate Contexts — one per type. An Organization with all three will have three Contexts in the admin.

Configuration surface per variant

Some tabs are shared across every Context; others appear only on specific variants:
TabDot1x (PEAP / EAP-TLS)iPSKRadius Proxy
Basic Configuration✓ (auth methods, Identity Store)✓ (CoA listeners, SGT, default roles)✓ (Default Device Group link)
Remote Radius Server
Default Group✓ (auto-created)
Attribute Profiles
Network Integration
Organization Common Settings

EntryPoint Context

The cross-cutting Context model.

Creating a Context

The wizard, start to finish.

Attribute Profiles

Reusable RADIUS-response bundles, attached per Group.

RADIUS clients

Hostname, ports, per-Context shared secret, CIDR allow-list.