Passbeam

How do personal or BYOD devices get on the network?

The honest answer is that a device gets a certificate or it does not get on, and how it gets one depends on whether you manage it.

Managed devices are the easy case. Anything enrolled in Intune or another MDM gets its certificate and its 802.1X settings pushed to it, without anybody touching the device. That covers company laptops and phones, and it is the path almost everything should be on.

A personal device you do not manage has two options, and neither is a password. You can issue a certificate to the person rather than the machine and let them install it — Passbeam produces the profile, and on iOS, macOS and Android that is a file they open. Or you leave them on guest, which for most visitors and most contractors is the right answer anyway: they get internet access and nothing else, and nobody has to trust a device they cannot see inside.

What Passbeam will not do is let a personal device on with a shared password, because that is the thing certificates exist to remove. If somebody needs real access from a machine you do not manage, the question worth asking is whether they should be reaching it through the VPN instead — the same certificate check, with a per-person rule about who may.

Related questions

Still stuck? Ask us, or read the rest of the knowledge base.