Passbeam

How do I set up BYOD so staff can add their own devices?

Staff open a link on their own iPhone or iPad, sign in with their school Microsoft account and install a Wi-Fi profile. The device gets its own certificate in their name and joins your BYOD network. There are no passwords to hand out, and when someone leaves or is taken out of the group, their devices stop connecting.

BYOD is billed per person, not per device. Each person can add up to three devices, and you can change that number.

Before you start. The client needs its Microsoft Entra connection set up, and you need to be able to add an SSID and a RADIUS profile in UniFi. iPhone and iPad work today. Android and Windows don't yet, and the onboarding page tells people so before they sign in.

1. Let staff sign in. Passbeam signs staff in through the app registration you already made for Passbeam in Entra, so there is no new app to approve. In the Entra admin center go to App registrations → All applications and open it. Its Application ID is shown on the client's BYOD page in Passbeam.

Open Authentication, click Add Redirect URI and choose Web. Enter https://passbeam.co.uk/onboard/callback, leave both token boxes unticked, and click Configure.

Microsoft Entra admin centerKestrel Primary School

App registrationsPassbeamAuthentication

Add Redirect URI · Web platform

Redirect URI

https://passbeam.co.uk/onboard/callback

Access tokens (used for implicit flows)

Unticked

ID tokens (used for implicit and hybrid flows)

Unticked

Configure
How this looks in Microsoft Entra admin center — drawn rather than captured, so the wording is theirs and none of it is anybody's real tenant.

Open API permissions, click Add a permission → Microsoft Graph → Delegated permissions, tick openid, profile and email, and click Add permissions. Then click Grant admin consent and confirm. Staff won't be asked to approve anything after that.

If the grant fails with "email does not exist in client application's RequiredResourceAccess", click Refresh and grant again. Entra sometimes takes a few seconds to save new permissions.

Microsoft Entra admin centerKestrel Primary School

App registrationsPassbeamAPI permissions

Configured permissions

+ Add a permissionGrant admin consent for Kestrel Primary School
PermissionTypeStatus
openidDelegatedGranted for Kestrel Primary School
profileDelegatedGranted for Kestrel Primary School
emailDelegatedGranted for Kestrel Primary School
User.Read.AllApplicationGranted for Kestrel Primary School
GroupMember.Read.AllApplicationGranted for Kestrel Primary School
How this looks in Microsoft Entra admin center — drawn rather than captured, so the wording is theirs and none of it is anybody's real tenant.

2. Add a Wi-Fi network for personal devices. Give BYOD its own SSID, so personal devices never share a network with the school's own. In UniFi Network go to Settings → Profiles → RADIUS and click Create New. Call it something like Passbeam (BYOD) and copy your existing Passbeam RADSec profile: TLS on, the same client certificate, private key and CA certificate, and both Passbeam addresses on port 2083. Tick Accounting Servers with the same addresses on port 1813.

On this profile only, tick RADIUS Assigned VLAN Support → Wireless Networks. That lets Passbeam put each staff group on its own VLAN, and because it's a separate profile, your other networks are never moved.

Check both servers are on 2083. A server on 1812 with TLS on gets nothing through, and the phone just fails to join.

UniFi Network · Settings · Profiles · RADIUS

Name

Passbeam (BYOD)

RADIUS Assigned VLAN Support

Wired Networks Wireless Networks
TLS
Client Certificatesame file as your Passbeam (RADSec) profile
Private Keysame file as your Passbeam (RADSec) profile
CA Certificatesame file as your Passbeam (RADSec) profile

Authentication servers

IP AddressPortShared Secret
Passbeam address 12083radsec
Passbeam address 22083radsec
Accounting Servers

Accounting servers

IP AddressPortShared Secret
Passbeam address 11813radsec
Passbeam address 21813radsec
Interim Update Interval300
A RADIUS profile just for BYOD. The same TLS files and Passbeam addresses as your existing RADSec profile, both on port 2083, and RADIUS-assigned VLANs ticked for wireless only.

Then create the SSID, for example School - BYOD, with WPA2 Enterprise security and the Passbeam (BYOD) profile.

3. Turn it on in Passbeam. Open the client and go to Access → BYOD. Under Settings, enter the SSID exactly as your access points broadcast it. Search for the Entra group allowed to join, for example All Staff, add it, and click Save. Then click Turn on.

Access → BYOD. Enter the SSID, choose who can join, save, then turn the link on.

4. Put each group on its own VLAN (optional). If your firewall filters by VLAN, this is how marketing can have social media and other staff don't. Open Sites, choose the site and go to VLANs. Add a rule for each group on the BYOD SSID, for example Marketing → VLAN 40 and All Staff → VLAN 30. The first matching rule wins, so put the narrower groups first.

For a personal device the rules read the owner's groups. Someone who matches no rule stays on the BYOD SSID's own VLAN, never the site's default. A new rule takes effect after the next directory check, within ten minutes.

Sites → your site → VLANs. One rule per group, on the BYOD SSID. Narrower groups first.

5. Share the link. Copy the onboarding link from the BYOD page, or put the QR code on the staffroom wall. It's the same link for everyone.

What staff do. They open the link in Safari, tap Sign in with Microsoft and sign in with their school account. Passbeam recognises the device and suggests a name. They tap Add this iPhone, then Download profile.

What staff see: the onboarding link, then their device and how many of their places are used.

iOS asks whether to allow the download. They tap Allow, then Close. If they have an Apple Watch, iOS asks which device the profile is for, and they choose iPhone.

Allow the download, then find it at the top of Settings, or under General → VPN & Device Management.

Next they open Settings, tap Profile Downloaded at the top, then Install, and enter their passcode. The profile shows Signed by passbeam.co.uk.

Install shows Signed by passbeam.co.uk. Tap Install, enter the passcode, and Install again.

Back in Safari, the page moves on by itself. It ticks off the certificate, then the Wi-Fi, and finishes on You're connected. From then on the device joins the BYOD network on its own.

Back in Safari the page moves on by itself and finishes on You're connected.
Installed, and joined to the BYOD network. From now on it connects by itself.

When someone leaves. Disable their account in Entra or take them out of the group. Within ten minutes their devices stop connecting, and nobody has to remove anything.

Removing a device. Staff can remove their own devices from the onboarding link, and you can remove any device from the BYOD page. Either way its certificate is revoked straight away and the device is refused the next time it signs in to the Wi-Fi.

If a device won't join, look at the client's Authentications. "This is a personal device, and its certificate only works on…" means it tried another SSID, or the SSID on the BYOD page doesn't match exactly. "…isn't in … any more" means the person was taken out of the allowed group. If nothing appears in the log at all, check the RADIUS profile's ports.

Related questions

Still stuck? Ask us, or read the rest of the knowledge base.