Can Passbeam replace our Windows NPS server?
Yes, and it is the most common reason people arrive here. NPS means a Windows server to patch, a certificate authority to run and back up, and a machine whose failure takes the Wi-Fi down with it. Passbeam is the same job with none of that at the client's site.
One thing to check before you plan the move, and it is the same check whichever cloud RADIUS you pick: what your NPS is actually authenticating. If it is doing EAP-TLS with certificates, this is a like-for-like replacement. If it is doing PEAP-MSCHAPv2 against domain passwords, it is not — Passbeam does no password-based EAP, so that is a change of method as well as a change of server, and every device needs a certificate before it can join. See “Do you support PEAP, MSCHAPv2 or EAP-TTLS?”.
The practical order is to run both for a while. Add Passbeam's two addresses to the RADIUS profile alongside the existing server, enrol a handful of devices, watch them authenticate in the log, then move the rest and take NPS out of the profile last. Nothing here requires the old server to be gone first.
The certificates do not carry over. Passbeam issues from an authority it provisions per client, so devices get a new certificate and a new trusted root, delivered through Intune or another MDM — which is also the point at which the old CA stops being something anybody has to keep alive.
Related questions
Still stuck? Ask us, or read the rest of the knowledge base.