Which switches do 802.1X properly, and which ignore re-authentication?
Passbeam works with any switch that speaks 802.1X to a RADIUS server, but switches differ in one thing that matters after the device is already connected: whether they re-authenticate. This table is what we have measured on our own hardware, and it is worth a minute before you rely on revocation being immediate.
Why re-authentication is the one to care about. A certificate is checked when a device joins. Revoking it stops the next join — it does not reach a link that is already up. So Passbeam asks the switch to re-run the check on a timer, by sending Session-Timeout with Termination-Action = RADIUS-Request on every accept. On equipment that honours it, a revoked certificate is off the network within the hour and nobody notices the re-check. On equipment that ignores it, the device keeps the access it was given until the port cycles — and this is invisible from the dashboard, which will show the certificate revoked while the device is still connected.
Where a switch ignores the timer, suspending the person or device in Entra ID still works exactly as it should; it simply does not take effect when you would expect. If that matters on a given site, the reliable lever is the port — bouncing it forces a fresh authentication.
| Equipment | 802.1X | Re-authenticates on our timer | How we know |
|---|---|---|---|
| UniFi USW Pro 48 PoE | Yes | Yes — hourly, on the dot | Measured 1 Sep 2026: 31 re-authentications over four days on a 3600s timer |
| UniFi US-8-150W | Yes | Not measured | Authenticated a printer on the first attempt; the interval was never timed |
| UniFi US-8-60W (Gen 1) | Yes | No | Measured 1 Sep 2026: 2 accepts over the same four days, on the same 3600s timer, against the Pro 48's 31 |
| UniFi USW Ultra and Flex Mini | No — the setting does not exist | — | Ubiquiti documents these two families as the exception; confirmed on a USW Ultra 60W, where there is nothing to switch on |
| Netgear GS724Tv4 | Setting exists, sends nothing | — | Measured: a complete, correct configuration, port reported Held, and zero Access-Requests ever left the switch |
Check your own rather than trusting this table. Set a re-authentication interval on the client's Access rules, then open the authentication log and count the accepts for one device over a few hours. One accept proves nothing — an interval needs two to show itself. If a device that has been connected all day has a single accept, that switch is not re-authenticating, whatever its datasheet says.
Anything not listed is almost certainly fine: this table exists because of the exceptions, not because support is narrow. See “Which switches and access points does Passbeam support?” for the general answer.
Related questions
- What happens when somebody leaves?
- Can I stop one device getting on without revoking its certificate?
- Can I restrict a network to one group?
- Can I refuse devices that Intune says are not compliant?
- Does this cover wired as well as wireless?
- How do personal or BYOD devices get on the network?
- How can I see which devices are connected right now?
- Sessions are empty. What do I need to turn on?
- Why does a wired session show no IP address or data usage?
Still stuck? Ask us, or read the rest of the knowledge base.