802.1X for printers, cameras and building controls — without a directory
A camera on the outside of a building is a network point on the outside of a building. Unplug it, plug in a laptop, and on most networks you are in. 802.1X is the fix — the port only comes up for a device that proves who it is with a certificate — and it has always been sold to networks full of people with accounts.
Passbeam does it for networks with nobody on them. Add the client as Appliances only and there is no directory to connect and no MDM to configure: a private certificate authority for that network, a certificate for each device, and a RADIUS server in the cloud that answers the switches. The same product every other client gets, with the parts that need a directory kept out of the way.
What this kind of network does not need
Said as a list, because each of these is the thing that has stopped somebody doing this before.
Not needed
- A Microsoft Entra ID tenant, or any directory
- An MDM — Intune, Jamf or otherwise
- A RADIUS server, NPS box or appliance at the site
- A certificate authority to build, secure and back up
- An agent on anything, or a change to the devices beyond their own 802.1X page
What is needed
- Devices with an 802.1X page in their web interface — most printers, cameras and controllers made in the last decade have one
- Switches or access points that can point at a RADIUS server
- Somebody to spend a few minutes per device, once
What goes on these ports
Anything with a web interface and an 802.1X page. The kinds that turn up most, and the one thing to know about each.
- Printers and MFPs
- Almost all speak EAP-TLS; many have one certificate slot shared with their own HTTPS page.
- IP cameras and NVRs
- The commonest reason a port needs locking — a camera outside is a network point outside.
- Door controllers and access panels
- Unattended, on the wall, and on the same switch as everything else.
- BMS, HVAC and plant controllers
- Long-lived hardware, often speaking older TLS; a per-site floor covers it.
- IoT sensors and gateways
- Anything with a web interface and an 802.1X page, whatever it is for.
How a camera gets on
- 1
Add the client as Appliances only
The question is asked when the client is created. Choose it and the checklist is three steps — the authority, the appliances, the network — with no directory and no MDM anywhere in it.
- 2
Passbeam runs a certificate authority for that network
One click. Private to this client and shared with no other organisation, with its own audit trail. Nothing to build, patch or back up.
- 3
Each device makes its own certificate request
In the device's web interface, under certificates, ask it to create a request. The private key is generated on the device and never leaves it — there is no file to lose on an installer's laptop. Paste the request into Passbeam and it hands back the signed certificate. A fleet tool can produce the requests in bulk, which is what makes a forty-camera site an afternoon rather than a week.
- 4
Install the certificate and the root
Both go into the device's own certificate slots: its certificate, and this client's root so that it trusts the network back. EAP-TLS is mutual, and the second half is the one people forget.
- 5
Point the switches at Passbeam
Two addresses and one secret per site, generated for you. RADSec where the equipment speaks it, standard RADIUS where it does not. The first device to authenticate proves the chain end to end.
- 6
The port comes up for the camera, and for nothing else
Every connection is checked against the certificate, its expiry and the revocation list. A laptop plugged into that port has no certificate from this authority, so it gets whatever the switch does with a failure — a guest VLAN, or nothing. The authentication log names the camera, so a port that stops working names the device rather than the site.
What a directory would have done, and what replaces it
On a network of people, Passbeam revokes a certificate when its Entra account is disabled. A camera has no account, so nothing withdraws its certificate on its own — when it is scrapped or replaced, revoking it is a job for a person, and it is one click in the Appliances list. Worth knowing before the first one is decommissioned rather than after.
Two things about the hardware itself, each with its own answer. Many printers and cameras have one certificate slot, shared between 802.1X and their own web page; there is a tick on the form for exactly that case. And some building controllers speak older TLS than a modern RADIUS server accepts, so the floor can be lowered for one site without touching any other.
By default an appliance may connect at any of that client’s sites. Open it from the list afterwards to pin it to particular ones, so a certificate issued for the depot does not open a port at head office.
If the building also has people in it
Then add the client the ordinary way — Entra ID and Intune, or Entra ID with another MDM — and use the Appliances tab for the kit. The same authority signs the laptops and the cameras, so there is one root to trust and one log to read, and a person’s certificate still dies with their account while the camera’s waits to be revoked by hand. Appliances only is for the network that has nothing else on it; it is not a lesser version for everyone else. The knowledge-base answer covers changing a client from one to the other later.
What it costs
A camera is a device. The first 10 devices on your account are free and stay free — enough to put a small site on it before deciding. After that it is £2.50 per device, per month, with no server licence underneath it and nothing to buy up front.
Set up your first network in under 30 minutes
Create your Passbeam account, add a client — a customer, your company, or your own house — and follow the guided checklist through Entra, PKI, Intune and RADSec. Three steps rather than four if it is a network of printers and cameras.