Network Access Control

Know exactly what is on your network. Control exactly what it can reach.

Pre-shared keys, unmanaged devices, and open network ports are the gaps compliance frameworks now require you to close. Edge7 Networks delivers cloud-native network access control as a managed service. Identity-verified, certificate-based, and segmented by role.

Cloud NAC hero illustration Cloud NAC Identity + compliance + access Corporate VLAN IoT segment Guest access Laptops Mobile IoT devices
The problem

Pre-shared keys are not access control.

Most enterprise networks still rely on pre-shared keys for WiFi access. One password, shared across the organisation, giving every device that knows it the same level of access.

That single credential cannot distinguish between a managed corporate laptop and a personal phone. It cannot check whether a device is patched, encrypted, or enrolled in device management. And it cannot segment traffic based on who or what is connecting.

Compliance frameworks. NIS2, Cyber Essentials, ISO 27001. They now require network segmentation and identity-based access control. Pre-shared keys do not meet that standard.

Flat network

Every device sees every other device. Printers on the same VLAN as finance systems.

No visibility

No audit trail of what connected, when, or what it accessed. No device classification.

No identity

Cannot distinguish a managed laptop from a personal phone. Everyone gets the same access.

Compliance gap

NIS2, ISO 27001, and Cyber Essentials all require segmentation. PSKs are not sufficient.

What changes

Six capabilities that replace shared passwords.

Identity-verified access

Authenticate users against your existing identity provider. Azure AD, Okta, Google Workspace.

Multi-IdP

AI device profiling

Automatically classify every device connecting to your network using machine-learning fingerprinting.

Automated

Certificate-based auth

EAP-TLS certificates replace passwords. Unique per device, auto-renewed, cryptographically secure.

EAP-TLS

Headless device support

Printers, cameras, sensors. MAC-based authentication for devices that cannot run a supplicant.

MAC auth

Guest access

Self-service onboarding with captive portal. Isolated VLAN, time-limited, fully audited.

Self-service

Cloud-native

No on-premises RADIUS. Managed entirely from the cloud. Included in your subscription.

Included

Identity-verified access

Every connection is authenticated against your identity provider before the device is granted any network access. Azure AD, Okta, Google Workspace, or on-premises Active Directory. No shared passwords. No anonymous connections. Each user gets a certificate tied to their identity, and the network assigns the correct VLAN and policy automatically.

Azure AD Okta Google Workspace On-prem AD Multi-IdP

AI device profiling

Machine-learning fingerprinting classifies every device connecting to your network. Laptops, phones, printers, cameras, IoT sensors. The platform builds a real-time inventory and applies the correct access policy without manual intervention. New device types are identified automatically as they appear.

ML fingerprinting Auto-classification Real-time inventory Policy mapping

Certificate-based authentication

EAP-TLS replaces passwords with unique per-device certificates. Each certificate is cryptographically bound to the device and user, auto-renewed before expiry, and revocable in real time. No password fatigue. No credential sharing. No phishable WiFi passwords. The certificate is enrolled silently via the Onboard app and managed entirely from the cloud.

EAP-TLS Auto-renewal Per-device certs Cloud PKI

Headless device support

Not every device can run a certificate supplicant. Printers, IP cameras, building sensors, medical devices. MAC-based authentication identifies these devices by their hardware address and places them into the correct restricted VLAN. Combined with AI profiling, the platform detects if a device type changes, preventing MAC spoofing attacks.

MAC auth IoT segmentation Spoof detection Restricted VLANs

Guest access

Visitors and contractors self-onboard through a branded captive portal. Sponsor approval, time-limited credentials, and automatic VLAN assignment keep guest traffic completely isolated from corporate resources. Full audit trail of every guest session. No IT overhead for day-to-day guest management.

Captive portal Sponsor approval Time-limited Isolated VLAN

Cloud-native platform

No on-premises RADIUS servers. No PKI infrastructure to maintain. Cloud Authentication runs entirely from HPE Aruba Central, included in your Edge7 managed network subscription. Updates, patches, and scaling are handled automatically. You get a single dashboard for policy, certificates, and device visibility across every site.

Aruba Central No RADIUS Auto-updates Subscription

What you no longer need to manage

On-prem RADIUS servers
Cloud-native auth
No hardware. No patching. No failover planning.
Internal PKI infrastructure
Managed cloud PKI
Certificates issued, renewed, and revoked from the cloud.
Shared WiFi passwords
Per-device certificates
No password rotation. No credential sharing. No PSKs.

The only MSP in Ireland and the UK offering Cloud NAC as a dedicated service.

802.1X authentication is the gold standard for network security. Aruba Central Cloud Authentication makes it achievable without the infrastructure overhead. No RADIUS servers. No on-premises PKI. Edge7 Networks designs, deploys, and manages Cloud NAC as a project or an ongoing service.

Talk to us about Cloud NAC
How it works

From connection to segmentation in seconds.

Step 1
Connect
Step 2
Identity
Step 3
Compliance
Step 4
Certificate
Step 5
Access
Step 6
Renewal

Connect

A device connects to a wired port or wireless SSID. The network port is in a closed state. No traffic passes until the device is authenticated. 802.1X enforcement begins immediately.

802.1XWired + wirelessPort-based

Identity

The device presents credentials. For managed devices, this is a certificate enrolled by the Onboard app. For users, identity is verified against your IdP. Azure AD, Okta, Google Workspace, or on-prem AD. The platform confirms who is connecting.

EAP-TLSMulti-IdPCertificate-based

Compliance

The platform checks device posture. Is the OS patched? Is encryption enabled? Is the device enrolled in Intune, Jamf, or your MDM? Non-compliant devices are quarantined or given restricted access until remediation is complete.

IntuneJamfPosture checkQuarantine

Certificate

A unique certificate is issued to the device, cryptographically binding user identity to device identity. Certificates are auto-enrolled via the Onboard app and auto-renewed before expiry. No user intervention required. Revocation is instant from the cloud dashboard.

Cloud PKIAuto-enrolAuto-renewInstant revocation

Access

The authenticated, compliant device is placed into the correct network segment. Role-based VLAN assignment, dynamic ACLs, and microsegmentation policies are applied automatically. Corporate devices reach corporate resources. Guest devices reach the internet. IoT devices reach only what they need.

Dynamic VLANRole-basedMicrosegmentationACLs

Renewal

Certificates renew automatically before expiry. Device posture is re-evaluated continuously. If a device falls out of compliance, its access is revoked or restricted in real time. No manual certificate management. No expiry outages.

Auto-renewalContinuous postureReal-time revocation

Compliant device

Identity verified, device healthy, certificate issued. Placed on the correct corporate VLAN with role-based access. Reconnects automatically.

Non-compliant or unknown

Missing patches, no enrolment, or unrecognised. Access refused or quarantined to a restricted segment with remediation instructions.

NIS2 ISO 27001 Cyber Essentials SOC 2 GDPR PCI DSS
The platform

Built on HPE Aruba Central Cloud Authentication.

HPE Aruba Central Cloud Authentication

Cloud-native 802.1X authentication and certificate authority. No on-premises RADIUS. No standalone PKI. Policy, certificates, and device visibility managed from a single dashboard. Integrated directly with your HPE Aruba network infrastructure and your identity providers.

Identity providers

  • Microsoft Azure AD / Entra ID
  • Okta
  • Google Workspace
  • On-premises Active Directory
  • LDAP

Device compliance

  • Microsoft Intune
  • Jamf Pro
  • VMware Workspace ONE
  • CrowdStrike Falcon
  • Custom MDM via API

Network infrastructure

  • HPE Aruba access points
  • HPE Aruba switches
  • HPE Aruba gateways
  • Third-party 802.1X switches
  • SD-WAN overlay integration
Included

Foundation licence

Cloud authentication, certificate authority, basic device profiling, VLAN assignment, and guest access. Included with your Edge7 managed network subscription.

Advanced

NAC Pro licence

AI-enhanced device profiling, advanced posture assessment, continuous compliance monitoring, and extended integration APIs for third-party MDM and SIEM platforms.

Onboard App platforms

Windows
macOS
iOS
Android
ChromeOS
HPE Aruba Networking Gold Partner Certified to design, deploy, and manage Aruba Cloud Authentication and NAC solutions.
Why Edge7 Networks

The only MSP delivering Cloud NAC as a dedicated service.

Most providers bolt network access control onto an existing contract as an afterthought. Edge7 Networks treats NAC as a first-class managed service with dedicated project delivery and ongoing operations.

Networking and security under one roof

NAC sits at the intersection of networking and security. Edge7 has both disciplines in-house. Your access control policy is designed by engineers who understand your switches, your firewalls, and your identity stack.

Project or managed service

Need NAC designed and deployed as a one-off project? We do that. Want it run as part of a fully managed network service? We do that too. Same team, same standards, your choice of engagement model.

Same team, year after year

No rotating contractors. No offshore escalation. The engineers who design your NAC deployment are the same engineers who manage it. They know your environment, your policies, and your compliance requirements.

Part of a broader managed network

NAC does not exist in isolation. It connects to your switches, your wireless, your SD-WAN, and your security stack. Edge7 manages the full picture, so your access control works with your infrastructure, not against it.

Frequently asked questions

Common questions about Network Access Control, 802.1X, and managed NAC services.

Network Access Control (NAC) is a security approach that restricts network access based on the verified identity of the connecting device, rather than relying on shared passwords or pre-shared keys (PSK). NAC uses certificate-based authentication. Typically 802.1X with EAP-TLS. To verify each device individually before granting access. Once connected, NAC enforces role-based network segmentation so devices only reach the resources they are authorised to use.

A firewall controls traffic between network segments after a device is already connected. Network Access Control (NAC) operates before the connection is established, determining whether a device is permitted to connect at all. NAC and firewalls are complementary controls: NAC governs who gets onto the network, while a firewall governs what a connected device can do once it is there.

Cloud NAC is a Network Access Control solution where the authentication and policy infrastructure runs in the cloud rather than on on-premises RADIUS servers. This removes the need to manage local authentication infrastructure, making enterprise-grade access control accessible to organisations without dedicated networking teams. Edge7 Networks delivers Cloud NAC as a dedicated managed service built on HPE Aruba Central Cloud Authentication. The only MSP in Ireland and the UK to offer this as a standalone managed service.

802.1X is an IEEE standard for port-based network access control. It defines a framework for authenticating devices before they are permitted to access a network, using a RADIUS server to validate credentials. In enterprise environments, 802.1X is typically combined with EAP-TLS certificate authentication to provide strong per-device identity verification without requiring users to enter passwords.

EAP-TLS (Extensible Authentication Protocol with Transport Layer Security) is the most secure 802.1X authentication method. It uses digital certificates rather than passwords to authenticate both the client device and the authentication server. Because each device holds a unique certificate that cannot be shared or guessed, EAP-TLS eliminates the credential-sharing risk that makes pre-shared key (PSK) authentication a common attack vector in Wi-Fi and wired environments.

Yes. IoT and OT devices that cannot run a certificate agent are handled using AI-powered device profiling, which identifies device type based on network behaviour and fingerprinting, then assigns the appropriate network segment automatically. Edge7 Networks' Cloud NAC service handles IT, IoT, and OT devices across the same policy framework, ensuring consistent access control regardless of device type.

Let us talk about what is on your network.

Whether you are preparing for a compliance audit, migrating away from pre-shared keys, or dealing with device sprawl across multiple sites, we can help.

HPE Aruba Gold Partner Dedicated NAC specialists Worldwide coverage Project or managed service