Contact Us

Migrate Windows NPS to the Cloud with EZRADIUS

Book Demo Start Free Trial

Retire Your On-Premises NPS Servers
and Save Up to 75% on RADIUS Costs

Replace aging NPS infrastructure with a cloud-native RADIUS solution built for modern
Microsoft Entra ID environments. No hardware, no patching, no surprises.

  • Eliminate NPS hardware, patching, and HA failover complexity
  • Only pay for the users and devices that authenticate each month
  • Keep your existing PKI: AD CS, Microsoft Cloud PKI, and EZCA all supported
  • Native Entra ID integration, no ghost accounts or workarounds
  • Export accounting and audit logs to your SIEM (Sentinel, Splunk, and more)
  • SOC 2 Type II & ISO 27001 certified infrastructure
1,000+
Customers trust EZRADIUS
for their Cloud RADIUS
45M+
RADIUS authentications
per month by EZRADIUS
10+
RADIUS Regions
to choose from
99.95%
Enterprise-Tier SLA

The NPS Problem Your IT Team Knows Too Well

NPS was built for a different era. Here's why organizations are moving on.

Problem

Legacy Infrastructure Overhead

NPS requires on-prem hardware or Azure VMs that need constant patching, monitoring, and failover management which costs cycles your team doesn't have.


EZRADIUS Solution

EZRADIUS handles patching, scaling, and failover automatically.
No servers to deploy, patch, or scale.

Problem

Entra ID Integration Gaps

NPS doesn't understand Entra ID natively. Workarounds like ghost accounts, AD sync dependencies, and manual group mappings create security blind spots and administrative debt.


EZRADIUS Solution

EZRADIUS integrates with Entra ID in real-time to authenticate users.
No ghost accounts, no sync lag.

Problem

HA Complexity & Hidden Costs

A proper high-availability NPS deployment requires redundant hardware or VMs, load balancers, health monitoring, and 24/7 on-call coverage to meet your SLA.


EZRADIUS Solution

EZRADIUS is multi-region and multi-AZ by default. Up to 99.95% uptime SLA for enterprise-grade deployments.

Problem

Device Compliance Blind Spot

NPS has no visibility into whether a device is Intune-managed or compliant. A compromised or unmanaged device looks identical to a healthy one at the RADIUS layer.


EZRADIUS Solution

EZRADIUS natively enforces Intune compliance at authentication time.
Only compliant, managed devices get on your network.

Migration in 3 Easy Steps. No Network Downtime.

It's easy to try out EZRADIUS alongside your existing NPS deployment and make the switch when you're ready.

1

Connect Your Existing PKI & Certificates

Add your AD CS, Microsoft Cloud PKI, or EZCA certificate authorities in just a few clicks. No changes to your existing certificate lifecycle.

2

Point Your Network to EZRADIUS

Update your network controllers to point to the closest EZRADIUS region. Classic RADIUS and RadSec both supported.

3

Authenticate to Your Networks

Client devices connect using their existing certificates and credentials. Windows, macOS, Android, iOS, and Linux all supported.

See Why Organizations Make the Switch

EZRADIUS was built by ex-Microsoft engineers who understand the challenges and limitations of NPS deployments.

Feature Windows NPS EZRADIUS
EAP-TLS Certificate Authentication
Native Entra ID Integration Workarounds only Real-time, no ghost accounts
Intune Device Compliance Enforcement Native, enforced at auth time
Multi-Region High Availability Manual, complex Built-in, up to 99.95% SLA
Zero Trust Network Access Limited Full compliance-gated access
Global/Multi-Office Endpoints Complex HA setup per site Simple global IPs, 10+ regions
Self-Service Portal for Unmanaged Devices
SIEM Integration (Sentinel, Splunk, etc.) Limited Full audit log export
No Hardware or VMs to Manage
No OS Patching Burden
Pay-as-you-go Pricing Per active user/device per month

Securely Authenticate Every User & Device

EZRADIUS supports the most popular authentication methods your organization relies on today

EAP-TLS

Existing PKI Infrastructure

  • Support for AD CS, Microsoft Cloud PKI, and third-party CAs
  • No disruption to existing certificate lifecycle or enrollment processes
  • No passwords to share, leak, or manage.
EAP-TTLS

Entra ID Credentials

  • Out-of-the-box support for Entra ID credentials without certificates
  • Real-time Entra ID access and group checks. No sync jobs required.
  • Perfect for BYOD or non-certificate use cases
MAB

MAC Address Bypass

  • Authenticate printers, IoT devices, and other non-certificate endpoints
  • Centrally manage and audit MAB devices in the EZRADIUS portal
  • Specify custom VLANs for MAB devices
Legacy

Legacy Protocol Support

  • Full support for PAP and MSCHAPv2 for backward compatibility
  • Ensures older devices and systems stay connected during migration
  • Migrate at your own pace without forcing a device refresh

Broad Ecosystem Support

EZRADIUS integrates seamlessly with your existing network infrastructure, MDM platforms, and client devices to ensure a smooth and secure migration.

EZRADIUS network architecture diagram—replaces Windows NPS with cloud-native RADIUS

Transparent Pricing

No hardware investment. No long-term contracts. No hidden fees. Just pay for what you use and cancel anytime.

Basic RADIUS

Fully-featured hosted Cloud RADIUS at an affordable price

$0 / month
Pay only for authenticated users & devices
  • Native Entra ID integration
  • Intune device compliance checks
  • Certificate-based authentication with EZCA, Microsoft Cloud PKI, or any 3rd party PKI
  • Support for EAP-TLS, TTLS, PAP, MSCHAPv2, and MAB protocols
  • Export RADIUS accounting logs + audit logs to your SIEM
  • Local RADIUS proxy for added availability + offline cache
  • Shared infrastructure
  • Choose from 10+ global regions
  • 99.9% availability SLA
  • Support within 1 business day

Dedicated RADIUS

Your own dedicated infrastructure with the same cloud convenience

$400 / month
Includes 200 users & devices
  • All the features of Basic, plus:
  • Network isolation to your IPs
  • Full dynamic IP support
  • Dedicated infrastructure
  • Choose a region closest to you
  • 24/7 support within 24 hours

Enterprise RADIUS

For global organizations with mission-critical workloads

$3,500 / month
Includes 10,000 users & devices
  • All the features of Dedicated, plus:
  • Azure GCC & GCC High Support
  • Select multiple regions near your global workforce
  • Up to 99.95% availability
  • 24/7 support within 1 hour

Per-User & Device Rates

We only charge for the users and devices that authenticate each month (minus included identities) and we cap your bill at the total number of users in your Entra ID tenant. No hidden fees, no long-term contracts.

Identity 1–500
$1 / month
Identity 501–1,000
$0.40 / month
Identity 1,001–10,000
$0.20 / month
Identity 10,000+
$0.10 / month
See Full Pricing Details & Calculator

No long-term contracts  ·  No hidden fees  ·  Cancel anytime

Ready to Decommission Your NPS Servers?

Start with a free trial, or book a free migration assessment. Our specialists will calculate your exact savings and build a risk-free migration plan tailored to your environment.

No credit card required  ·  No long-term contracts  ·  Free migration assessment included

Frequently Asked Questions

Is there a trial available?

Yes! You can start a free trial of EZRADIUS today with no credit card required. Experience the benefits of cloud RADIUS firsthand and see how easy it is to migrate from NPS.

How do I know if EZRADIUS is right for my organization?

If you're looking to reduce the overhead of managing on-prem NPS servers, improve security with native Entra ID integration, and save costs with a pay-as-you-go model, then EZRADIUS is a great fit. We recommend starting with a free migration assessment to see the potential benefits for your specific environment.

How long does migration typically take?

Migration timelines can vary based on the size and complexity of your environment, but many organizations are able to complete the migration from NPS to EZRADIUS within a few days. Because there's no hardware to deploy and no complex HA setup required, the process is often much faster than traditional RADIUS migrations. We recommend starting with a free migration assessment to get a better idea of the timeline for your specific environment.

How does the migration process work?

You can run EZRADIUS in parallel with your existing NPS deployment to test and validate in your environment. When you're ready, simply update your network controllers to point to EZRADIUS and decommission your NPS servers at your own pace.

Can I run EZRADIUS alongside NPS during migration?

Yes! You can run EZRADIUS in parallel with your existing NPS deployment to test and validate in your environment. When you're ready, simply update your network controllers to point to EZRADIUS and decommission your NPS servers at your own pace.

Will I need to change my existing certificates or PKI setup?

No changes needed. EZRADIUS supports your existing AD CS, Microsoft Cloud PKI, or third-party CAs. Just add your CA certificates to your EZRADIUS policy and optionally issue a new server certificate from your existing CA and you're good to go.

Can I use my existing AD CS certificates?

Yes! You can use your existing AD CS certificates with EZRADIUS. Just add your CA certificates to your EZRADIUS policy and optionally issue a new server certificate from AD CS and you're good to go.

Do I need Entra ID P1/P2 licenses?

No, EZRADIUS does not require any specific Entra ID licenses. You can use your existing Entra ID tenant and user accounts without needing to purchase additional licenses. We integrate with Entra ID using the Microsoft Graph API, so we can authenticate users and check group memberships in real-time without any dependency on specific license tiers.

What network vendors are supported?

EZRADIUS supports nearly every network controller that supports RADIUS or RadSec. Simply point it at the EZRADIUS IP addresses and you're good to go. For a full list of our tested and validated network vendors, check out our supported network vendors page.

What if I have a global workforce with multiple offices?

EZRADIUS has 10+ global regions to choose from, so you can select the one closest to each of your offices for optimal performance. Our Dedicated and Enterprise plans also offer custom regions, network isolation, and dynamic IP support for complex global deployments.

Do I need to change tiers or plans if I add more users or offices?

No, EZRADIUS is designed to scale seamlessly with your organization. You can add more users or offices without needing to change your existing plan, and you only ever pay for the users and devices that authenticate each month. There are no plan limits on the number of users, devices, or offices you can have.