PortGuardNAC
  • Why PortGuard
  • Features
  • Use Cases
  • Pricing
  • Partners
  • Docs
  • Contact
🔐 Partner Login Book a Demo
Why PortGuard Features Use Cases Pricing Partners Docs Contact
Book a Demo →
// Admin Guide

3. Identity

PortGuard v1.1.10 · ← Administrator’s Guide · Documentation

Users — local RADIUS accounts

Local accounts authenticate over 802.1X with username and password (PEAP-MSCHAPv2) when you are not using an external directory.

Adding a user

  1. Open Users → Add Local RADIUS User: username, password, group, and optionally a VLAN (if empty, the group default applies).
  2. Save — the account is active on the RADIUS service immediately, no restart needed.

Users can be edited, disabled or deleted at any time; every change is written to the audit log.

Groups

Groups bundle users to assign a default VLAN in one place and to be referenced in policies. Create a group with name, default VLAN, description and enabled flag. A user without an explicit VLAN inherits the group’s.

Identity Federation

Connects the appliance to your corporate directories. Each provider has its own card on the page.

Microsoft Entra ID (Azure AD)

  1. Register an application in your Entra tenant. You need the Tenant ID, Client ID and Client Secret, with Graph read permissions for users and groups (add Device.Read.All if you want device names resolved too).
  2. Enter the credentials in the Microsoft Entra ID card and save.
  3. Select the groups to synchronize: members (users and devices) are imported and kept aligned by the periodic sync (configurable interval).
  4. Synced identities can then be used in policies (group / domain conditions) and are recognized in EAP-TLS logons (user@domain) and machine logons (host/PCNAME is matched to the Entra device — the Devices page then shows it as domain/PCNAME).

LDAP / LDAPS

For on-premises Active Directory: server URL, Bind DN and password, user and group Base DNs, and customizable filters (default (sAMAccountName={username})).

SAML 2.0

IdP metadata (URL or XML), entity ID, ACS URL, signing certificate, and attribute mapping (username, email, display name, groups) under Claims Mapping.

Provider priority

Provider Control defines which source wins when the same identity exists in several providers (default order: local, ldap, saml, entra).

Sync status and troubleshooting

Sync Status shows the last synchronization result and member counts per group; Troubleshooting / Sync Logs exposes detailed Graph/LDAP errors for diagnosis.

Tip: a full walk-through of the Entra ID setup, including the app registration screens, is in the dedicated Entra ID Integration article.

← 2. Monitoring
4. Network Access Control →
PortGuardNAC
© 2026 Valerio Lollini / CrazyNet.
Why PortGuard Features Use Cases Pricing Partners Docs Status Support
Made with ♥ in Proudly built in Italy 🇮🇹
Privacy Policy· Cookie Policy· Terms of Service· EULA
CrazyNet · St Julian's, Malta · [email protected]
🍪 Cookies on this site

We only use essential technical cookies for authenticated areas — no tracking, no profiling, no third-party cookies. See our Cookie Policy.

PortGuardNAC AssistantAsk about features, setup, pricing
AI assistant — may be imperfect. For quotes or account issues, email [email protected].