Cloud RADIUS with native support for Microsoft Cloud PKI

Trust Microsoft Cloud PKI in just a few clicks and authenticate Wi-Fi, VPN, and network access with the certificates you already issue to your devices.

Integrates with

Microsoft Cloud PKI Entra ID Intune Azure Marketplace Sentinel MACC
  • Trust Microsoft Cloud PKI in just a few clicks, no PKI rebuilds or additional chaining
  • Native Entra ID authentication and Intune compliance checks, enforced in real time
  • Instant revocation for rolled or retired devices and users, no waiting on CRLs
  • Deploys from the Azure Marketplace and bills to your subscription and MACC commitments

1,200+

Global organizations
trust Keytos

45M+

RADIUS authentications
per month by EZRADIUS

12+

RADIUS regions to choose from for low latency

99.95%

Enterprise-tier service availability

4.8/5

G2 Users Love Us badge G2 High Performer, Fall 2026 badge

"No server deployment needed for wireless authentication with Entra credentials. Straightforward setup, and the organization eliminated its on-premises RADIUS server entirely by moving to a fully cloud-based infrastructure."

Renzo Patricio C. · Senior System Administrator

Why Microsoft Cloud PKI customers choose EZRADIUS

Learn why Microsoft Cloud PKI customers choose EZRADIUS to add cloud RADIUS authentication to their Intune environment


  • Trust Microsoft Cloud PKI in just a few clicks and use your existing certificates

  • Instant revocation the moment a device or user is rolled or retired with no CRL propagation delay

  • Native Entra ID auth and Intune compliance, checked in real time at every connection

  • Deploys from the Azure Marketplace and billed directly to your Azure subscription and MACC commitments

  • No VMs or infrastructure to manage. EZRADIUS is a fully managed cloud RADIUS SaaS service

  • Free 1-month trial before you pay a cent, with no sales call required

  • Deploy and start authenticating in minutes, not days

Other cloud RADIUS providers


  • Extra chaining or a separate certificate authority before Cloud PKI certificates are trusted

  • Access relies on CRL updates that can take hours or days to propagate after a device is retired

  • No visibility into Intune for compliance checks or device inventory

  • Entra ID and Intune bolted on after the fact, if supported at all

  • Sold outside Microsoft channels with no Azure billing or MACC credit

  • No free trial, or a hard, sales-gated evaluation

  • Days or weeks of setup before the first authentication

Keep the PKI you already run

EZRADIUS authenticates against the certificates Microsoft Cloud PKI issues today, with nothing to rebuild and no revocation lag to work around.

Trust Cloud PKI in a few clicks

Point EZRADIUS at your Microsoft Cloud PKI root and issuing CAs. Devices already enrolled and certified through Intune can authenticate immediately, with no PKI rebuild or extra chaining.

Instant revocation, no CRL wait

EZRADIUS checks Entra ID and Intune status in real time, so rolled or retired devices and users lose access immediately instead of waiting hours or days for a CRL to propagate.

Entra ID auth and Intune compliance

Authenticate users against Entra ID and evaluate Intune device compliance at the moment of connection, so only managed, compliant devices reach your network.

Buy it the way you buy Azure

EZRADIUS is on the Azure Marketplace and bills to your Azure subscription and resource group, counting toward MACC commitments for eligible enterprise agreements.

Trusts the certificates Microsoft Cloud PKI already issues

EZRADIUS connects directly to Microsoft Cloud PKI, Entra ID, and Intune, so devices already enrolled and certified through Intune can authenticate immediately, with no separate certificate strategy to build and no CRL infrastructure to maintain.

EZRADIUS connected to Microsoft Cloud PKI, Entra ID, and Intune for certificate-based network authentication

Up and running with Cloud PKI in 3 easy steps

No separate certificate strategy to build, no CRL infrastructure to babysit. Connect the Microsoft Cloud PKI you already have and start authenticating in minutes.

01

Deploy EZRADIUS in Azure

Deploy EZRADIUS from the Azure Marketplace in just a few clicks, with no servers or VMs to buy or maintain.

02

Connect your Cloud PKI

Point EZRADIUS at your Microsoft Cloud PKI root and issuing CAs in just a few clicks.

03

Start authenticating

Point your network devices to the EZRADIUS global set of IPs and start authenticating your Cloud PKI-issued certificates.

EZRADIUS with Microsoft Cloud PKI

Transparent pricing

No hardware investment. No long-term contracts. No hidden fees. Just pay for what you use and cancel anytime.

Dedicated

All the convenience of hosted RADIUS with your own dedicated infrastructure

  • Everything in Basic, plus:
  • First 200 active identities included
  • Full dynamic IP address RADIUS support
  • Dedicated infrastructure for only your users and devices
  • Choose a single region closest to you
  • 24/7 support within 24 hours

Monthly subscription cost

$400 USD
(includes 200 active identities)

Monthly cost per active identity

First 200Included in subscription
Next 300$1 USD each
Next 500$0.40 USD each
Next 9,000$0.20 USD each
Anything above$0.10 USD each
Book a demo

Enterprise

Custom, multi-region deployments with the highest SLAs and support

  • Everything in Dedicated, plus:
  • First 10,000 active identities included
  • Multi-region with zonal/geo redundancy
  • Custom hosting options
  • Up to 99.95% SLA
  • 24/7 support within 1 hour

Monthly subscription cost

$3,500 USD
(includes 10,000 active identities)

Monthly cost per active identity

First 10,000Included in subscription
Anything above$0.10 USD each
Book a demo
See full pricing details & calculator

Ready to put Microsoft Cloud PKI to work in your RADIUS?

Start your free 1-month trial today, trust Microsoft Cloud PKI in just a few clicks, and get instant revocation instead of waiting on CRL updates.

Frequently asked questions

Yes. EZRADIUS connects directly to Microsoft Cloud PKI's root and issuing CAs, so devices and users with certificates already issued through Intune can authenticate immediately, with no separate certificate authority to stand up.

Just a few clicks. Add your Microsoft Cloud PKI root and issuing CAs and it starts trusting Cloud PKI-issued certificates right away.

Yes. EZRADIUS checks Entra ID and Intune status in real time, so rolled or retired devices and users lose network access immediately. Other cloud RADIUS providers rely on Certificate Revocation Lists (CRLs), which can take hours or even days to propagate.

Yes. EZRADIUS evaluates Intune device compliance at the moment of authentication, so only managed, compliant devices are granted network access.

Yes. EZRADIUS is available on the Azure Marketplace and bills directly to your Azure subscription and resource group, alongside the rest of your Azure spend.

No. EZRADIUS is built to work with the certificate infrastructure you already have. It trusts Microsoft Cloud PKI, AD CS, and other certificate authorities without requiring you to rip and replace anything.

Yes. New customers get a free 1-month trial before any charges apply, so you can validate EZRADIUS against your own Microsoft Cloud PKI environment before committing.