What does Passbeam actually do?
Two things that normally need two products and a server. It runs a certificate authority for each of your clients, and it answers the network authentication requests your equipment makes when a device tries to join — 802.1X, over RADIUS or RADSec.
The result is that a laptop or phone joins the network with a certificate rather than a password, and that certificate is checked on every single connection — that it is one of this client's, that it has not expired, and that it has not been revoked. Passbeam keeps that revocation list in step with your client's Microsoft 365 accounts, so a disabled account stops getting on. Nobody types a shared key, and there is no shared key to leak.
It covers wireless and wired equally. The same certificate that gets a laptop onto the SSID gets it onto a switch port, and Passbeam can put it on a different VLAN depending on who or what it is.
And it does the same for things that have no account and no MDM — printers, cameras, door controllers, building management — which get a certificate each from the same authority and authenticate the same way. A client can be nothing but those, with no directory behind it at all.
Related questions
Still stuck? Ask us, or read the rest of the knowledge base.