In many companies, access to the Wi-Fi network or to network equipment still relies on a single shared password known by everyone: employees, contractors, former employees, visitors. It is the easiest thing to set up and, at the same time, one of the weakest links in the security chain. RADIUS authentication solves exactly this problem by shifting access control from "one password per device" to "one identity per user".
What a RADIUS server actually does
RADIUS (Remote Authentication Dial-In User Service) is a standardized protocol that lets network devices — access points, switches, firewalls, VPN gateways — delegate access decisions to a central server. That server answers three core questions, known as AAA:
- Authentication — who is trying to connect?
- Authorization — what are they allowed to reach, in which VLAN, under which policy?
- Accounting — when did they connect, for how long, from which device?
In practice, the RADIUS server usually does not store passwords itself. It is typically integrated with Active Directory or another identity directory, so every employee uses the same credentials as for their work computer.
How RADIUS relates to 802.1X
IEEE 802.1X is the mechanism through which a switch port or a wireless connection stays closed until the user or device proves its identity. Three parties are involved:
- Supplicant — the client (laptop, phone, printer).
- Authenticator — the switch or access point holding the gate shut.
- Authentication server — the RADIUS server validating the credentials.
Only after RADIUS confirms the identity does the network device open access and apply additional policies: automatic VLAN assignment, ACLs, bandwidth limits. On wireless, this setup is called WPA2-Enterprise or WPA3-Enterprise, as opposed to the Personal variant built around a shared passphrase.
The practical benefits
Individual credentials instead of a shared secret
The biggest gain is traceability. Every connection maps to a user account, not to an anonymous password. When someone leaves the company, disabling their Active Directory account instantly removes their access to Wi-Fi, VPN and network gear. There is no need to change the Wi-Fi password and redistribute it to everyone else — a task that in reality keeps getting postponed.
Automatic network segmentation
The RADIUS server can return attributes telling the switch or access point which VLAN to place the client in. On the same physical infrastructure you can cleanly separate:
- the employee network;
- a guest network isolated from internal resources;
- IoT devices, cameras and printers;
- endpoints in sensitive areas, under stricter policies.
Segmentation meaningfully reduces the attack surface: a compromised device on the guest network cannot reach the file server or the ERP.
Certificate-based authentication
Modern methods such as EAP-TLS remove the password from the equation entirely. The device authenticates with a certificate issued by an internal certificate authority. This is the strongest option against phishing and credential stuffing, because there is no secret the user can accidentally disclose.
A single point of administration
Access policies are written once, on the server, and enforced across all sites and all devices. For companies with multiple offices or mixed-vendor equipment, RADIUS is the common denominator: being a standard protocol, it is supported by virtually every professional network device, including Fortinet firewalls and access points.
Audit-ready logs
The accounting component produces exactly the kind of evidence an audit asks for: who connected, from which device, at what time, for how long. For organizations in scope of NIS2, access control and identity management measures are part of the Article 21 requirements, and centralized authentication with verifiable records is a far stronger argument than a shared Wi-Fi password.
What to plan for during implementation
RADIUS is not a switch you flip and forget. A few aspects deserve attention from the start:
- Redundancy. If the RADIUS server goes down, authentication fails. Plan for at least two servers and clear fallback policies on the network devices.
- Transport. Classic RADIUS uses UDP and a shared secret. For inter-site traffic, consider RadSec (RADIUS over TLS) or a dedicated tunnel.
- Devices without 802.1X support. Printers, cameras, sensors — these rely on MAC Authentication Bypass, keeping in mind that a MAC address can be spoofed, which is why such devices belong in a restricted VLAN.
- Device inventory. Before enabling 802.1X on switches, you need to know exactly what is plugged into the network, or you risk production outages.
- Phased rollout. The safest path is to start with corporate Wi-Fi, then VPN, then wired access ports, with a monitoring period in permissive mode.
Conclusion
RADIUS authentication turns your network from a space open to anyone who knows a password into an infrastructure where every access is identified, authorized and logged. It is a mature security control, compatible with the equipment you most likely already own, and a solid foundation for segmentation, Zero Trust and compliance.
Designing and integrating such a system does require attention to detail: Active Directory integration, certificate lifecycle management, VLAN policies and handling of legacy devices. If you are considering the move from a shared Wi-Fi password to per-user authentication, an assessment of your current infrastructure and a phased migration plan, carried out with a team experienced in networking and security, will spare you downtime and unpleasant surprises in production.