How do I set up BYOD so staff can add their own devices?
Staff open a link on their own iPhone or iPad, sign in with their school Microsoft account and install a Wi-Fi profile. The device gets its own certificate in their name and joins your BYOD network. There are no passwords to hand out, and when someone leaves or is taken out of the group, their devices stop connecting.
BYOD is billed per person, not per device. Each person can add up to three devices, and you can change that number.
Before you start. The client needs its Microsoft Entra connection set up, and you need to be able to add an SSID and a RADIUS profile in UniFi. iPhone and iPad work today. Android and Windows don't yet, and the onboarding page tells people so before they sign in.
1. Let staff sign in. Passbeam signs staff in through the app registration you already made for Passbeam in Entra, so there is no new app to approve. In the Entra admin center go to App registrations → All applications and open it. Its Application ID is shown on the client's BYOD page in Passbeam.
Open Authentication, click Add Redirect URI and choose Web. Enter https://passbeam.co.uk/onboard/callback, leave both token boxes unticked, and click Configure.
App registrationsPassbeamAuthentication
Add Redirect URI · Web platform
Redirect URI
https://passbeam.co.uk/onboard/callback
Access tokens (used for implicit flows)
Unticked
ID tokens (used for implicit and hybrid flows)
Unticked
Open API permissions, click Add a permission → Microsoft Graph → Delegated permissions, tick openid, profile and email, and click Add permissions. Then click Grant admin consent and confirm. Staff won't be asked to approve anything after that.
If the grant fails with "email does not exist in client application's RequiredResourceAccess", click Refresh and grant again. Entra sometimes takes a few seconds to save new permissions.
App registrationsPassbeamAPI permissions
Configured permissions
| Permission | Type | Status |
|---|---|---|
| openid | Delegated | Granted for Kestrel Primary School |
| profile | Delegated | Granted for Kestrel Primary School |
| Delegated | Granted for Kestrel Primary School | |
| User.Read.All | Application | Granted for Kestrel Primary School |
| GroupMember.Read.All | Application | Granted for Kestrel Primary School |
2. Add a Wi-Fi network for personal devices. Give BYOD its own SSID, so personal devices never share a network with the school's own. In UniFi Network go to Settings → Profiles → RADIUS and click Create New. Call it something like Passbeam (BYOD) and copy your existing Passbeam RADSec profile: TLS on, the same client certificate, private key and CA certificate, and both Passbeam addresses on port 2083. Tick Accounting Servers with the same addresses on port 1813.
On this profile only, tick RADIUS Assigned VLAN Support → Wireless Networks. That lets Passbeam put each staff group on its own VLAN, and because it's a separate profile, your other networks are never moved.
Check both servers are on 2083. A server on 1812 with TLS on gets nothing through, and the phone just fails to join.
Name
RADIUS Assigned VLAN Support
Wired Networks Wireless NetworksAuthentication servers
Accounting servers
Then create the SSID, for example School - BYOD, with WPA2 Enterprise security and the Passbeam (BYOD) profile.
3. Turn it on in Passbeam. Open the client and go to Access → BYOD. Under Settings, enter the SSID exactly as your access points broadcast it. Search for the Entra group allowed to join, for example All Staff, add it, and click Save. Then click Turn on.
4. Put each group on its own VLAN (optional). If your firewall filters by VLAN, this is how marketing can have social media and other staff don't. Open Sites, choose the site and go to VLANs. Add a rule for each group on the BYOD SSID, for example Marketing → VLAN 40 and All Staff → VLAN 30. The first matching rule wins, so put the narrower groups first.
For a personal device the rules read the owner's groups. Someone who matches no rule stays on the BYOD SSID's own VLAN, never the site's default. A new rule takes effect after the next directory check, within ten minutes.
5. Share the link. Copy the onboarding link from the BYOD page, or put the QR code on the staffroom wall. It's the same link for everyone.
What staff do. They open the link in Safari, tap Sign in with Microsoft and sign in with their school account. Passbeam recognises the device and suggests a name. They tap Add this iPhone, then Download profile.
iOS asks whether to allow the download. They tap Allow, then Close. If they have an Apple Watch, iOS asks which device the profile is for, and they choose iPhone.
Next they open Settings, tap Profile Downloaded at the top, then Install, and enter their passcode. The profile shows Signed by passbeam.co.uk.
Back in Safari, the page moves on by itself. It ticks off the certificate, then the Wi-Fi, and finishes on You're connected. From then on the device joins the BYOD network on its own.
When someone leaves. Disable their account in Entra or take them out of the group. Within ten minutes their devices stop connecting, and nobody has to remove anything.
Removing a device. Staff can remove their own devices from the onboarding link, and you can remove any device from the BYOD page. Either way its certificate is revoked straight away and the device is refused the next time it signs in to the Wi-Fi.
If a device won't join, look at the client's Authentications. "This is a personal device, and its certificate only works on…" means it tried another SSID, or the SSID on the BYOD page doesn't match exactly. "…isn't in … any more" means the person was taken out of the allowed group. If nothing appears in the log at all, check the RADIUS profile's ports.
Related questions
- How do I set up Microsoft sign-in (SSO) for Passbeam?
- What happens when somebody leaves?
- Can I stop one device getting on without revoking its certificate?
- Can I restrict a network to one group?
- Can I refuse devices that Intune says are not compliant?
- Does this cover wired as well as wireless?
- Which switches do 802.1X properly, and which ignore re-authentication?
- How do personal or BYOD devices get on the network?
- How can I see which devices are connected right now?
- Sessions are empty. What do I need to turn on?
- Why does a wired session show no IP address or data usage?
Still stuck? Ask us, or read the rest of the knowledge base.