Everything it does
The detail that used to be on the front page, grouped by what you are trying to do rather than by how it is built.
Added this month
Live sessions
Your equipment reports who joins, stays and leaves. The Sessions tab shows who is on right now, the address or switch port they hold, how long they have been there and how much they have moved.
It answers “which device had 10.6.101.42 at three o’clock”, which nothing else here can.
RADIUS accounting
Served on 1813, over TLS or plain UDP. Point your controller’s accounting server at the same addresses you already use, with the same shared secret.
Four session states, and the honest ones matter: we say when equipment has gone quiet rather than guessing the device left.
VPN gateway authentication
A firewall doing IKEv2 authenticates its users against Passbeam, with the certificate that already gets their laptop onto the office network. Optionally narrowed to an Entra group, optionally with Duo as a second factor.
One disabled account closes the desk, the Wi‑Fi and the VPN together.
Disconnect a live device
A small container on the site’s own network carries the request inwards, so there is no inbound rule and it works behind NAT or CGNAT. Passbeam builds and signs the packet; the container never holds your shared secret.
The reply’s signature is checked before the portal will tell you the device came off.
Three ways in
- Entra ID and IntuneMain road
- Passbeam builds the profiles, Intune pushes them, and every managed device requests its own certificate. Access dies with the account.
- How the Intune path works →
- Entra ID with another MDM
- Jamf, Mosyle, Kandji, or a profile you build yourself. Passbeam issues the enrolment challenge and still checks Entra on every request.
- Using another MDM →
- No directory at all
- Printers, cameras, door access, building controls. A certificate each from the same authority, checked on every connection.
- 802.1X for appliances →
What Passbeam actually is
You already have the directory and the network. Passbeam is everything in between.
- Identity
- Entra ID
- Users and devices come from your client's existing directory. Passbeam reads account and device status from it — there is no second directory to keep in step, and no accounts to create here.
- Certificates
- A private CA per client
- Passbeam provisions and runs a separate issuing certificate authority for each client, with its own audit trail. No CA server to build, patch or back up.
- Enrolment
- SCEP, through Intune
- You click once in Passbeam and Intune does the rest. Every managed device gets its own certificate and its Wi-Fi or wired settings, without anybody touching the device or typing a password into it. On another MDM, Passbeam hands you the three values its SCEP profile needs. For a printer or a camera, it issues the certificate by hand from the same authority.
- Authentication
- Access points, switches, VPN gateways
- EAP-TLS over RADSec, or standard RADIUS where the equipment has no RADSec — any make, from UniFi and Meraki to Cisco, Aruba, Juniper and Arista. Every handshake is checked against the certificate, the revocation list and the account's live Entra status, and can refuse devices Intune reports as non-compliant.
Four steps, once per client
Each client gets its own certificate authority, its own Entra connection, and its own audit trail — separated by default, with nothing to configure to keep it that way.
- A
Connect their directory
Register an application in your client's Entra tenant, with the minimum permissions needed to read account and device status. Passbeam walks you through every screen and then proves the connection works before letting you move on. A network of cameras and printers with no directory skips this step — Passbeam does not ask for one.
- B
Create their authority
One click. Choose whether this client's certificates identify users, devices, or both — Passbeam generates the authority and keeps it separate from every other client's.
- C
Paste the profiles into Intune
Passbeam builds them all — the certificate profile, the Wi-Fi profile, the wired network profile, and a small script that starts the Windows service wired 802.1X depends on — filled in with this client's own values. Copy them across and assign them, and Intune takes it from there: each device or user requests its own certificate over SCEP, without anybody visiting a desk. Using Jamf, Mosyle or Kandji instead? Passbeam issues an enrolment challenge for their SCEP payload and checks Entra on every request just the same.
- D
Point your network at the endpoint
Two addresses and one credential per site, generated for you. Paste them into your controller or switch configuration — UniFi, Cisco, Meraki, Aruba, Juniper, Arista or anything else that speaks RADIUS — over RADSec where the equipment offers it, standard RADIUS where it does not. The first device to connect proves the whole chain end to end.
Built for people who run other people's networks, and for people who run their own
One product, one set of features, however many networks you look after. Passbeam calls each one a client — and what that means depends on you.
- Managed service providers
- A client is a customer.
- Multi-tenant cloud PKI and 802.1X, built for running networks you don't own. Every customer gets their own certificate authority, their own directory connection and their own audit trail — separated by default. Their access points, switches and VPN gateways all authenticate against one place, with no RADIUS server to patch at three in the morning.
- Businesses
- A client is your own company.
- Every company that takes security seriously ends up with the same question: who is actually on the network? A shared Wi-Fi password is known by everyone who ever worked here. Passbeam gives each device or user its own certificate and checks it against your Microsoft 365 accounts on every connection — access points, switches and VPN gateways alike. Printers and cameras get one too, so a spare port in the plant room is as locked as the one under a desk.
- Home labbers
- A client is your house.
- This is where it starts, and we mean that — most of us got here by running enterprise kit at home for no reason other than wanting to. So it is the same product, not a demonstration of one: your own certificate authority, and real EAP-TLS on the access points, switches and VPN gateway already in your cupboard. Entra ID is free and Intune is not, so you do not need it here. 10 devices free, permanently. Then take it to work on Monday.
Set up your first network in under 30 minutes
Create your Passbeam account, add a client — a customer, your company, or your own house — and follow the guided checklist through Entra, PKI, Intune and RADSec. Three steps rather than four if it is a network of printers and cameras.
Designed for