Networking

ClearPass or Cloud Auth: Choosing a NAC Model You Won't Regret

ClearPass and Cloud Auth do access control in different ways. Here is how to tell which one your estate needs.

E7
Edge7 Networks Team
Solutions Architecture, Networking
26 June 2026
8 min read
Share

Two NAC models, one estate

Aruba gives you two ways to do network access control. ClearPass Policy Manager is the on-premises policy engine. Cloud Auth is cloud-native and built into Central. They sit at different points on a curve of policy depth against operational effort. Picking the wrong one is expensive to undo. This is how we decide.

What ClearPass is for

ClearPass is the heavyweight. It runs RADIUS and TACACS+. It profiles devices in depth. It handles guest, certificate onboarding, and posture through OnGuard. Its policy engine weighs many attributes at once. You can gate a contractor laptop on ownership, patch state, agent, location and time, then assign a role.

That depth costs operational effort. ClearPass is infrastructure you run, on-premises or virtual. It needs sizing, patching, and someone who knows its policy model. The effort pays off with complex wired 802.1X, strict posture, TACACS+, or in-house authentication. For a simple wireless estate it is more than the job needs.

What Cloud Auth is for

Cloud Auth is delivered inside HPE Aruba Networking Central. There is no policy manager to stand up. It authenticates against Microsoft Entra ID or Google. It uses multi pre-shared key (MPSK) to segment headless and IoT devices without certificates. It profiles clients with the same agentless Client Insights data as Central.

For an organisation whose identity lives in the cloud, it covers most access needs with less to run. You give up depth. The multi-attribute conditional policy and heavy posture work stay with ClearPass.

The decision axes that matter

Strip the feature lists and a few questions settle it.

If you need…Lean ClearPassLean Cloud Auth
Policy depthComplex, multi-attribute, conditionalClean, IdP-driven, role-based
Posture assessmentYes, via OnGuardNot the strength
Device admin (TACACS+)YesNo
Identity sourceOn-prem AD, mixedCloud IdP (Entra, Google)
Operational overheadYou run the platformDelivered in Central
Air-gapped / in-house authYesCloud-dependent
IoT / headless segmentationProfiling + policyMPSK + Client Insights

Answer them and the choice is usually clear. The trap is buying ClearPass depth you never operate. The other trap is picking Cloud Auth and hitting a posture or TACACS+ need you waved away.

They can coexist

This is not always one or the other. A large estate can run both. Use ClearPass where depth is needed: complex campus, regulated site, wired 802.1X with posture. Use Cloud Auth where identity is cloud-based and needs are simpler. Give each a clear boundary. Do not run both by accident with overlapping responsibility.

Roles and segmentation

The admission decision matters less than the role assigned with it. NAC decides who and what a device is. That identity drives policy across the fabric. In AOS-10 it feeds dynamic segmentation and NetConductor. A role set at authentication becomes enforcement wherever the traffic goes.

This is where network access control meets identity and Zero Trust. Role accuracy depends on device profiling. The agentless Client Insights data feeds both models.

From the field

Profiling accuracy is the quiet dependency

Both models depend on device profiling. Misidentify an IoT device and you block something valid or trust something you should not. Get a clear picture of what is on the network before you choose.

How we'd choose

We start from the requirement. How complex does the policy need to be. Are posture and TACACS+ real needs. Where does identity live. Who will run it. Those answers settle most cases. Then we design the role and segmentation model. Then we confirm profiling is solid enough to trust the roles.

We run network access control on both ClearPass and Cloud Auth. If you are choosing, a short design conversation usually settles it.


E7
Edge7 Networks Team
Solutions Architecture · Networking, Ireland & UK

Written by the Edge7 Networks networking practice. the architects and engineers who design, migrate, and run these environments day to day. Edge7 Networks is a specialist networking and security provider, founded in 2018, and an HPE Aruba Networking partner working with IT leaders across Ireland and the UK. We hold ISO 27001:2022, ISO 9001:2015, and Cyber Essentials certifications.

Deciding on a NAC model?

Our architects design and run ClearPass and Cloud Auth across Ireland and the UK. If you would like to talk through your access control, we are easy to reach.