Skip to content
Concepts

Comparing variants

A side-by-side matrix of the EntryPoint variants — EAP-PEAP, EAP-TLS with Device cert, EAP-TLS with Microsoft Entra ID, iPSK, and Radius Proxy — so you can pick the right one for each audience.

Every EntryPoint Context picks a variant in the Create RADIUSaaS Context wizard. Each variant serves a distinct audience; most Organizations run more than one Context to cover all their audiences.

Variant dropdown in the Create RADIUSaaS Context wizard
Create RADIUSaaS Context wizard — variant dropdown.

The wizard offers three options (verbatim):

  • EntryPoint 2.0 (Dot1x PEAP, Entra) — hosts EAP-PEAP and EAP-TLS Groups. In this documentation we describe the method families as separate chapters — see EAP-PEAP, EAP-TLS with Device cert and EAP-TLS with Microsoft Entra ID — because they serve different audiences.
  • EntryPoint 2.0 (Radius Proxy / eduroam) — see Radius Proxy.
  • EntryPoint 1.0 (IPSK) — see iPSK for Cisco Networks.
  • EntryPoint 2.0 (EasyPSK) — the primary delivery of EasyPSK for Cisco Networks: per-unit keys for Cisco Meraki and Catalyst 9800, resolved over RADIUS, with three security flavours and per-group controls. Documented under EasyPSK via RADIUS.
EAP-PEAPEAP-TLS — Device certEAP-TLS with EntraiPSK for CiscoRadius Proxy
Wizard variantDot1x PEAP, EntraDot1x PEAP, EntraDot1x PEAP, EntraIPSKRadius Proxy / eduroam
Primary audienceAny audience with a username+password identity — employees, contractor firms, vendor teams, event cohorts, studentsManaged and unattended equipment — laptops, kiosks, headless gearEmployees on MDM-enrolled devicesIoT fleets on Cisco Wi-Fieduroam visitors; roaming partners
CredentialUsername + password (auto-generated)A certificate that names the deviceA certificate that names the userPer-Group shared PSKUpstream decides
Identity sourcePersonal PEAP Accounts held in EntryPointYour own PKI (Trusted CAs); optional Microsoft Entra device groupsMicrosoft Entra ID group membership (required)Device MAC → GroupRemote RADIUS server
Groups per ContextMany (one per audience)Many (one per device class, routed by Certificate Group Identifier)Many (one per Entra user group)Many (one per device class)Exactly one (Default Device Group)
Group-to-Entra-group mappingOptionalRequired
Self-Service portalYes (per-user Personal PEAP Account + per-OS setup guides)NoNoYes (Group admin + PSK admin + device admin)No
MAB fallbackInside Device-Cert Groups (shared with EAP-TLS)Inside Device-Cert Groups— (MAB lives on Device-Cert Groups)— (MAB sent by WLAN becomes iPSK)
Device Compliance Check (Intune)
Bulk device import✓ (CSV)
Typical VLAN strategyOne VLAN per audience (or shared across similar audiences)One VLAN per device classOne VLAN per roleOne VLAN per device classOne VLAN for visitors
Typical Group namesCorporate Staff, Acme Consulting, HVAC Contractors, Summer Interns 2026Managed Laptops, Reception Kiosks, Factory WorkstationsCorporate Staff, Finance, EngineeringRobot Cleaners, Digital Signage, Smart Locks, Lab SensorsDefault Device Group
  • Corporate staff with MDM-enrolled devices → EAP-TLS with Microsoft Entra ID. Cert-based auth, Entra group mapping, Intune posture.
  • Managed and unattended equipment — laptops, kiosks, headless gearEAP-TLS with Device cert. Certificates issued from your own PKI, devices routed by Certificate Group Identifier, no Entra required (Entra device groups optional).
  • Anyone on a password identity you want delegated admin for → EAP-PEAP. Contractor firms, vendor teams, event cohorts, flex-workforce pools, and staff without certificates, each on Personal PEAP Accounts held in EntryPoint. One Group per audience, one lead per Group, each audience runs itself.
  • Printers, VoIP phones, sensors, other non-802.1X gear behind the same VLAN as managed devices → MAB inside a Device-Cert Group (part of the EAP-TLS variant).
  • IoT on Cisco Wi-Fi, owned by different internal / vendor teams → iPSK. One Group per device class, distributed administration via Self-Service.
  • Visiting researchers / eduroam federation → Radius Proxy. Forward to the federation; no local identities.
  • Short-stay visitors on a captive portal → not EntryPoint. See Sign In.
  • Shared-SSID, per-unit residential keys (apartments, co-living), residents self-serve → EasyPSK, delivered as an EntryPoint 2.0 (EasyPSK) Context over RADIUS (Cisco Meraki and Catalyst 9800), or as a Meraki WPN Context. See EasyPSK for Cisco Networks.

A single EntryPoint 2.0 (Dot1x PEAP, Entra) Context can host EAP-PEAP and EAP-TLS Groups together — two independent master toggles on Client Authentication Methods. See Combining with EAP-TLS & MAB and Combining with EAP-PEAP.

Variants of different wizard types (Dot1x, iPSK, Radius Proxy) are separate Contexts — one per type. An Organization with all three will have three Contexts in the admin.

Some tabs are shared across every Context; others appear only on specific variants:

TabDot1x (PEAP / EAP-TLS)iPSKRadius Proxy
Basic Configuration✓ (auth methods, Identity Store)✓ (CoA listeners, SGT, default roles)✓ (Default Device Group link)
Remote Radius Server
Default Group✓ (auto-created)
Attribute Profiles
Network Integration
Organization Common Settings

Next