Passbeam

Everything it does

The detail that used to be on the front page, grouped by what you are trying to do rather than by how it is built.

Added this month

Three ways in

Entra ID and IntuneMain road
Passbeam builds the profiles, Intune pushes them, and every managed device requests its own certificate. Access dies with the account.
How the Intune path works
Entra ID with another MDM
Jamf, Mosyle, Kandji, or a profile you build yourself. Passbeam issues the enrolment challenge and still checks Entra on every request.
Using another MDM
No directory at all
Printers, cameras, door access, building controls. A certificate each from the same authority, checked on every connection.
802.1X for appliances

What Passbeam actually is

You already have the directory and the network. Passbeam is everything in between.

Identity
Entra ID
Users and devices come from your client's existing directory. Passbeam reads account and device status from it — there is no second directory to keep in step, and no accounts to create here.
Certificates
A private CA per client
Passbeam provisions and runs a separate issuing certificate authority for each client, with its own audit trail. No CA server to build, patch or back up.
Enrolment
SCEP, through Intune
You click once in Passbeam and Intune does the rest. Every managed device gets its own certificate and its Wi-Fi or wired settings, without anybody touching the device or typing a password into it. On another MDM, Passbeam hands you the three values its SCEP profile needs. For a printer or a camera, it issues the certificate by hand from the same authority.
Authentication
Access points, switches, VPN gateways
EAP-TLS over RADSec, or standard RADIUS where the equipment has no RADSec — any make, from UniFi and Meraki to Cisco, Aruba, Juniper and Arista. Every handshake is checked against the certificate, the revocation list and the account's live Entra status, and can refuse devices Intune reports as non-compliant.

Four steps, once per client

Each client gets its own certificate authority, its own Entra connection, and its own audit trail — separated by default, with nothing to configure to keep it that way.

  1. A

    Connect their directory

    Register an application in your client's Entra tenant, with the minimum permissions needed to read account and device status. Passbeam walks you through every screen and then proves the connection works before letting you move on. A network of cameras and printers with no directory skips this step — Passbeam does not ask for one.

  2. B

    Create their authority

    One click. Choose whether this client's certificates identify users, devices, or both — Passbeam generates the authority and keeps it separate from every other client's.

  3. C

    Paste the profiles into Intune

    Passbeam builds them all — the certificate profile, the Wi-Fi profile, the wired network profile, and a small script that starts the Windows service wired 802.1X depends on — filled in with this client's own values. Copy them across and assign them, and Intune takes it from there: each device or user requests its own certificate over SCEP, without anybody visiting a desk. Using Jamf, Mosyle or Kandji instead? Passbeam issues an enrolment challenge for their SCEP payload and checks Entra on every request just the same.

  4. D

    Point your network at the endpoint

    Two addresses and one credential per site, generated for you. Paste them into your controller or switch configuration — UniFi, Cisco, Meraki, Aruba, Juniper, Arista or anything else that speaks RADIUS — over RADSec where the equipment offers it, standard RADIUS where it does not. The first device to connect proves the whole chain end to end.

Built for people who run other people's networks, and for people who run their own

One product, one set of features, however many networks you look after. Passbeam calls each one a client — and what that means depends on you.

Managed service providers
A client is a customer.
Multi-tenant cloud PKI and 802.1X, built for running networks you don't own. Every customer gets their own certificate authority, their own directory connection and their own audit trail — separated by default. Their access points, switches and VPN gateways all authenticate against one place, with no RADIUS server to patch at three in the morning.
Businesses
A client is your own company.
Every company that takes security seriously ends up with the same question: who is actually on the network? A shared Wi-Fi password is known by everyone who ever worked here. Passbeam gives each device or user its own certificate and checks it against your Microsoft 365 accounts on every connection — access points, switches and VPN gateways alike. Printers and cameras get one too, so a spare port in the plant room is as locked as the one under a desk.
Home labbers
A client is your house.
This is where it starts, and we mean that — most of us got here by running enterprise kit at home for no reason other than wanting to. So it is the same product, not a demonstration of one: your own certificate authority, and real EAP-TLS on the access points, switches and VPN gateway already in your cupboard. Entra ID is free and Intune is not, so you do not need it here. 10 devices free, permanently. Then take it to work on Monday.

Set up your first network in under 30 minutes

Create your Passbeam account, add a client — a customer, your company, or your own house — and follow the guided checklist through Entra, PKI, Intune and RADSec. Three steps rather than four if it is a network of printers and cameras.

Designed for

Entra IDIntune