Local accounts authenticate over 802.1X with username and password (PEAP-MSCHAPv2) when you are not using an external directory.
Users can be edited, disabled or deleted at any time; every change is written to the audit log.
Groups bundle users to assign a default VLAN in one place and to be referenced in policies. Create a group with name, default VLAN, description and enabled flag. A user without an explicit VLAN inherits the group’s.
Connects the appliance to your corporate directories. Each provider has its own card on the page.
Device.Read.All if you want device names resolved too).user@domain) and machine logons (host/PCNAME is matched to the Entra device — the Devices page then shows it as domain/PCNAME).For on-premises Active Directory: server URL, Bind DN and password, user and group Base DNs, and customizable filters (default (sAMAccountName={username})).
IdP metadata (URL or XML), entity ID, ACS URL, signing certificate, and attribute mapping (username, email, display name, groups) under Claims Mapping.
Provider Control defines which source wins when the same identity exists in several providers (default order: local, ldap, saml, entra).
Sync Status shows the last synchronization result and member counts per group; Troubleshooting / Sync Logs exposes detailed Graph/LDAP errors for diagnosis.
Tip: a full walk-through of the Entra ID setup, including the app registration screens, is in the dedicated Entra ID Integration article.