How-To: Enable Cloud RADIUS with Entra ID Authentication in TP-Link Omada

Learn how to securely log into your TP-Link Omada network using Cloud RADIUS with Entra ID authentication.

Having a single Wi-Fi password for your network is a security nightmare. It’s impossible to know who has access to your network, and it’s nearly impossible to change the password regularly without causing major outages. The best way to secure your TP-Link Omada network is to use WPA-Enterprise with either certificates or individual user accounts for authentication.

To protect your TP-Link Omada network using certificates or Entra ID accounts, you will need a RADIUS server to handle authentication requests. EZRADIUS is a cloud-based RADIUS as a Service that integrates directly with Entra ID to provide secure authentication for your TP-Link Omada network without needing to manage any RADIUS servers or infrastructure. Simply add EZRADIUS as a RADIUS server in your TP-Link Omada Controller, and your users can log in using either passwordless certificates or their Entra ID username and password.

Overview of RADIUS Authentication with EZRADIUS

Want to follow along with step-by-step instructions? Check out our end-to-end YouTube video guides to follow along with setting up Cloud RADIUS in your TP-Link Omada Network.

How to Create an EZRADIUS Subscription

An EZRADIUS billing subscription is required to create your cloud-based RADIUS server for your TP-Link Omada network. If you do not already have an EZRADIUS subscription, follow this guide to create one.

Create an EZRADIUS Subscription

How to Set Up User Credentials for Cloud RADIUS

If you haven’t configured your authentication method yet, make sure to set that up before proceeding. This ensures that your users can authenticate properly when they connect to your TP-Link Omada network.

How to Set Up Passwordless Certificate Authentication with RADIUS

Certificates are the best way to authenticate users or devices without the need for any passwords. Simply connect to the network and the certificate will handle the authentication for you. This is the most secure and user-friendly way to authenticate users in your TP-Link Omada network.

While EZRADIUS supports any X.509 certificate such as ADCS and Microsoft Cloud PKI, the easiest way to create and manage certificates for your users is to use Keytos EZCA, a cloud-based PKI service that integrates directly with EZRADIUS. It only takes a few minutes to get started with EZCA and begin issuing certificates for passwordless Wi-Fi access in your TP-Link Omada network.

Deploy Passwordless Certificates

How to Set Up Entra ID Users to Authenticate with RADIUS

Don’t want to manage certificates? No problem! You can authenticate your existing Entra ID users using their username and password without needing to manage any PKI infrastructure.

Note that if you have conditional access policies set up in Entra ID (such as MFA), you will need to add an exception for EZRADIUS in order for username/password authentication to work. View this page for more details on adding this exception.

Configure Conditional Access Exception

How to Set Up Local Users to Authenticate with RADIUS

Have legacy devices or non-Entra ID users? You can also create local users directly in EZRADIUS and authenticate them using their username and password. Check out this page for more information on creating local users in EZRADIUS or letting your Entra ID users self-register local RADIUS accounts if needed.

Create Local RADIUS Users

How to Set Up Your Cloud RADIUS Access Policies for Entra ID Authentication

An EZRADIUS Access Policy defines how EZRADIUS will authenticate users when they connect to your TP-Link Omada network. You will need to create at least one access policy in EZRADIUS before you can connect your TP-Link Omada network to EZRADIUS.

How to Create a Passwordless Certificate Access Policy

A certificate access policy allows you to accept X.509 certificates for authentication and determine which users or devices are allowed to connect to your TP-Link Omada network. View this guide to learn how to create a certificate access policy in EZRADIUS if you have not already done so.

Create Certificate Access Policy

How to Create an Entra ID Username and Password Access Policy

An Entra ID username and password access policy allows you to authenticate your Entra ID users using their existing credentials. View this guide to learn how to create an Entra ID username and password access policy in EZRADIUS if you have not already done so.

Create Entra ID Password Access Policy

How to Create a Local Username and Password Access Policy

A local username and password access policy allows you to authenticate users that you have created directly in EZRADIUS. View this guide to learn how to create a local username and password access policy in EZRADIUS if you have not already done so.

Create Local User Access Policy

The following steps will guide you through the process of setting up Cloud RADIUS for your TP-Link Omada network using EZRADIUS.

Now that you have your EZRADIUS subscription and access policy set up, you can add EZRADIUS as a RADIUS server in your TP-Link Omada Controller.

Now that you have added EZRADIUS as a RADIUS server within TP-Link Omada, you can add it to your network so that when users connect to that network, they will be authenticated via EZRADIUS.

  1. Now that we have added the RADIUS profile, we need to go to Wireless Networks and the WLAN tab on the left.

    How to Add RADIUS Server for Entra ID in TP-Link Omada Network WIFI Controller

  2. In this tutorial we are going to assume that you have not created your network, but you can go in and modify an existing. But in this case we will click Create New Wireless Network.

    How to Add RADIUS Server for Entra ID in TP-Link Omada Network WIFI Controller

  3. Enter the SSID for your network.

  4. Select the bands you want to use for this network.

  5. Select WPA Enterprise for the Security.

  6. Select the RADIUS profile you created in the RADIUS Profile dropdown.

  7. Click on Apply In the bottom left. How to Add Entra ID Authentication in TP-Link Omada Network WIFI Controller

  8. Now that you have added the RADIUS profile to your network, you can connect your devices to your network using Entra ID authentication or local RADIUS accounts.

How to Push the RADIUS CA Certificate and Wi-Fi Profile Using Microsoft Intune

Follow these Intune step-by-step guides to push the required CA certificate and Wi-Fi profile to your users’ devices so they can seamlessly connect to your TP-Link Omada network using Cloud RADIUS.

Microsoft Intune Guide

How to Push the RADIUS CA Certificate and Wi-Fi Profile Using Jamf Pro

Follow these Jamf Pro step-by-step guides to push the required CA certificate and Wi-Fi profile to your users’ devices so they can seamlessly connect to your TP-Link Omada network using Cloud RADIUS.

Jamf Pro Guide

How to Manually Configure the RADIUS CA Certificate and Wi-Fi Profile on Your Devices

Follow these manual configuration step-by-step guides to manually configure the required CA certificate and Wi-Fi profile on your users’ devices so they can connect to your TP-Link Omada network using Cloud RADIUS.

Manual Configuration Guide

Not able to connect to your TP-Link Omada network after setting up EZRADIUS? Refer to this troubleshooting guide to help diagnose and resolve common issues when using Cloud RADIUS with TP-Link Omada.

Troubleshooting Guide

We also have a detailed video guide to help you troubleshoot common Cloud RADIUS issues with TP-Link Omada below: