Cloud NAC: network access control delivered as a cloud service
Cloudi-Fi runs 802.1X authentication and policy enforcement from the cloud. Your switches, access points and controllers stay in place as enforcement points, with no NAC appliance or per-site RADIUS server to build and maintain.

What is cloud NAC?
The same 802.1X, RADIUS and EAP-TLS protocols, with the policy decision moved to the cloud
Cloud NAC (Cloud Network Access Control) is a network access control service where the RADIUS policy engine runs in the cloud instead of on a local appliance. Your switches and access points forward authentication requests to the service, which checks the identity and returns the access policy to apply.
The protocols stay the same: 802.1X, RADIUS and EAP-TLS. The decision moves to the cloud, and one policy set covers every site, wired and Wi-Fi.
How cloud NAC works
This is the standard 802.1X exchange, and it completes in a few hundred milliseconds.
- A user or endpoint plugs into a switch port or associates with an SSID.
- The switch, access point or controller acts as the authenticator and opens a RADIUS request to the cloud service.
- The cloud engine checks the credential against a trusted source: Microsoft Entra ID, LDAP or Active Directory, a client certificate, or an approved MAC address.
- The engine answers with RADIUS attributes describing the access level, such as a VLAN identifier, a role name or an ACL.
- The switch or controller applies those attributes to the port or the wireless session.
- The service records the result and keeps the session data available for audit across all sites.
Cloud NAC vs on-premises NAC appliances
Traditional NAC puts a policy server, and usually a high-availability pair, in every data centre or large site. That model works, but the operational load grows with the number of locations.
| Area | On-premises NAC appliance | Cloud NAC |
|---|---|---|
| Infrastructure | Physical or virtual appliance per site or region | No local server to deploy |
| Resilience | HA pair and disaster recovery node to size and test | Handled by the service |
| Upgrades | Firmware and patch cycles owned by your team | Managed centrally, no maintenance window per site |
| Policy management | Policy sets replicated per deployment, prone to drift | One policy set applied everywhere |
| Adding a site | New node to install, license and integrate | Point the network device at the cloud service |
| Scaling | Sized on peak authentication load | Scales with the service |
Authentication methods
Endpoints vary in what credentials they can present, so the service accepts several methods at different assurance levels.
Certificate-based authentication (EAP-TLS)
EAP-TLS is the recommended method for managed users and devices. It removes shared passwords and uses the PKI you already run. Your MDM distributes the certificates, including Microsoft Intune.
802.1X with directory credentials
Authenticate corporate identities against Microsoft Entra ID, LDAP or Active Directory, and drive access decisions from group membership you already maintain. See our 802.1X cloud-ready feature for the full authentication detail.
MAC authentication bypass (MAB)
MAC authentication bypass is a controlled fallback for printers, sensors and other endpoints that cannot run a supplicant. The service identifies these devices by MAC address and places them in a restricted segment instead of granting them default access.
Segmentation and least-privilege access
Authentication identifies the device. The attributes returned with the acceptance decide what it can reach on the network. Cloudi-Fi Cloud NAC supports the ones your equipment already understands:
- Dynamic VLAN assignment based on user identity or device type
- Role-based access for employees, contractors and departments
- Isolation or quarantine for unknown and unmanaged endpoints
| Identity or device | Method | Access returned |
|---|---|---|
| Employee, Finance group | EAP-TLS | VLAN 40, full corporate access |
| Contractor | 802.1X, directory | VLAN 55 with restrictive ACL |
| IoT sensor | MAB | VLAN 90, isolated |
| Unknown device | No valid credential | Quarantine or no access |
Works with your existing network
Cloudi-Fi Cloud NAC is a RADIUS service, so any device that supports 802.1X and RADIUS can act as the enforcement point. There is no hardware to replace: Cisco Meraki, Cisco Catalyst 9800 WLC, Aruba, Fortinet and other 802.1X equipment are all supported.
Browse the deployment guides for vendor-specific configuration.
Corporate access and guest access on one platform
Cloudi-Fi Cloud NAC covers employees and managed devices. Visitors, contractors and personal devices go through Cloudi-Fi's cloud captive portal for self-registration and sponsored access, administered from the same console with one set of logs.
Where Cloudi-Fi Cloud NAC fits best
- Multi-site organisations with many small locations where a local NAC node is disproportionate
- Networks with a large IoT footprint, where unmanaged devices currently connect through open ports
- SASE and Zero Trust programs that extend verification down to the port and the SSID
- Post-merger environments where two directories and two network estates need one access policy
- Appliance end-of-life, as an alternative to buying the next generation of hardware

Start with Cloudi-Fi Cloud NAC

Instant, secure access to everything, anywhere
One solution for heterogeneous technology platforms and vendors
Integrated with the best technologies on the market
Infrastructure agnostic and plug-and-play deployment: rapidly roll-out Cloudi-Fi across global sites with any infrastructure provider

Cloud native, borderless, scalable and global!
Unlocking Universal Zero Trust Network Access on all continents
One platform for all industries
Cloudi-Fi empowers organizations with a scalable, cloud-based solution to secure users, devices, and data. Designed to integrate seamlessly into existing infrastructures.




