# Portnox Cloud User Guide ## Quick start - Quick start - [Quick start: RADIUS/NAC](topics/quick_start.md): In this topic, you will learn the first steps that you need to take to use Portnox™ Cloud for RADIUS network authentication and network access control. - [Quick start: TACACS+](topics/tacacs_quick_start.md): In this topic, you will learn the steps you need to take to configure and run the Portnox™ Cloud TACACS+ service. - [Quick start: ZTNA](topics/zero_trust_network_access_quick_start.md): In this topic, you will learn the steps you need to take to configure the Portnox™ Zero Trust Network Access service. - [About Portnox Cloud](topics/about.md): In this topic, you will learn about the basic concepts behind Portnox™ Cloud and its architecture. - [Name change: CLEAR → Cloud](topics/clear.md): In this topic, you will learn about the consequences of the name change from Portnox™ CLEAR to Portnox Cloud. ## Technology concepts - Technology concepts - [Secure networks](topics/concepts_secure_networks.md): In this topic, you will learn about the shortfalls of traditional networking and solutions that improve your network security to avoid being hacked. - [Secure resources](topics/concepts_secure_resources.md): In this topic, you will learn how Portnox ZTNA uses certificates – the same ones used for network access – to provide secure and controlled access to third-party applications and services \(referred to as resources\). This includes SSO-enabled web applications as well as on-premises resources like local web applications, allowing both local and remote users to safely connect to cloud resources and securely access on-premises and private cloud environments. - [Passwordless authentication](topics/concepts_passwordless.md): In this topic, you will learn what passwordless authentication is, why it offers stronger security and better user experience than traditional passwords, and how it is not a new idea but remains underused. You will also see how passwordless methods integrate with secure networking to reduce risks and improve access control. - [Risk assessment](topics/concepts_risk_assessment.md): In this topic, you will learn how continuous risk assessment evaluates the security posture of devices and users, ensuring that access is granted only to trusted, uncompromised endpoints. - [Interoperability](topics/concepts_integrations.md): In this topic, you will learn how secure networking and secure resources rely on strong integration with your existing software and systems, and what options Portnox provides to achieve this interoperability. ## Accessing Portnox Cloud - Accessing Portnox Cloud - [Sign up for Portnox Cloud](topics/signup.md): In this topic, you will learn how to sign up for a 30-day trial of Portnox™ Cloud by creating a Portnox ID. This will create your Portnox Cloud [tenant](glossary.md#). During the trial period, you have access to all functions of Portnox Cloud. - [Log in to Portnox Cloud](topics/login.md): In this topic, you will learn how to log in to Portnox™ Cloud using Portnox ID or a web login provider. - [Manage your administrator account](topics/admin_account.md): In this topic, you will learn how to manage your Portnox™ Cloud administrator account. - [Manage the organization data](topics/admin_organization.md): In this topic, you will learn how to manage your organization data in Portnox™ Cloud. - [Manage other administrator accounts](topics/admin_administrators.md): In this topic, you will learn how to manage Portnox™ Cloud administrator accounts other than yours. ## Managing RADIUS services - Managing RADIUS services - [How do RADIUS servers work in Portnox Cloud?](topics/radius_about.md): In this topic, you will learn the difference between cloud RADIUS and local RADIUS servers in Portnox™ Cloud. - [Set up a local RADIUS server using a virtual machine](topics/radius_local.md): In this topic, you will learn how to install and run local RADIUS servers that work together with Portnox™ Cloud using virtual machines. - [Run the local RADIUS server in Microsoft Hyper-V](topics/radius_local_hyperv.md): In this topic, you will learn how to install and configure the Portnox™ Cloud local RADIUS proxy in the Microsoft Hyper-V hypervisor. - [Run the local RADIUS server in VMware vSphere \(ESXi\)](topics/radius_local_vsphere.md): In this topic, you will learn how to install and configure the Portnox™ Cloud local RADIUS server in the VMware vSphere ESXi hypervisor. - [Run the local RADIUS server in VMware Workstation](topics/radius_local_vmware.md): In this topic, you will learn how to install and configure the Portnox™ Cloud local RADIUS server in the VMware Workstation hypervisor. - [Run the local RADIUS server in Oracle VirtualBox](topics/radius_local_virtualbox.md): In this topic, you will learn how to install and configure the Portnox™ Cloud local RADIUS proxy in the Oracle VirtualBox hypervisor. - [Run the local RADIUS server in a container](topics/radius_local_docker.md): In this topic, you will learn how to deploy the Portnox™ Cloud local RADIUS server using Docker containers. - [Deploy the local RADIUS server container in Microsoft Azure](topics/radius_local_azure.md): In this topic, you will learn how to deploy the Portnox™ Cloud local RADIUS server container in Microsoft Azure using Azure Container Instances. - [Deploy the local RADIUS server container in Amazon Web Services \(AWS\)](topics/radius_local_aws.md): In this topic, you will learn how to deploy the Portnox™ Cloud local RADIUS server container in Amazon Web Services \(AWS\) using AWS Fargate. - [Deploy the local RADIUS server container in Google Cloud Platform \(GCP\)](topics/radius_local_gcp.md): In this topic, you will learn how to deploy the Portnox™ Cloud local RADIUS server container in Google Cloud Platform \(GCP\) using the Google Compute Engine \(GCE\). - [Deploy the local RADIUS server container using Docker on Linux](topics/radius_local_linux.md): In this topic, you will learn how to deploy the Portnox™ Cloud local RADIUS server container using Docker on a local Linux machine \(physical or virtual\). - [Deploy the local RADIUS server container using Docker Desktop on Windows](topics/radius_local_windows.md): In this topic, you will learn how to deploy the Portnox™ Cloud local RADIUS server container using Docker Desktop on a local Windows machine \(physical or virtual\). - [Enable the RADIUS Change of Authorization feature](topics/radius_coa.md): In this topic, you will learn how to set up your environment to let Portnox™ Cloud send RADIUS Change of Authorization \(CoA\) packets to your NAS devices when you change access policies. - [Create Cloud RADIUS servers](topics/radius_create.md): In this topic, you will learn how to create Cloud RADIUS servers in Portnox™ Cloud for your organization. - [Configure advanced RADIUS server options](topics/radius_advanced.md): In this topic, you will learn how to configure advanced options for Cloud RADIUS servers in Portnox™ Cloud. - [Configure RADIUS forwarding rules](topics/radius_forwarding.md): In this topic, you will learn how to configure forwarding rules for Cloud RADIUS servers. ## Integrating with authentication repositories - Integrating with authentication repositories - [How it works](topics/integrate_auth.md): - [Integrate with Microsoft Entra ID](topics/integrate_entra.md): In this topic, you will learn how to integrate Portnox™ Cloud with Microsoft Entra ID services. - [Integrate with Entra ID using multiple applications](topics/integrate_entra_multiple.md): In this topic, you will learn how to integrate Portnox™ Cloud with Microsoft Entra ID services by creating multiple Portnox Cloud applications. - [Integrate with Entra ID using manual provisioning](topics/integrate_entra_manual.md): In this topic, you will continue Portnox™ Cloud integration with Entra ID using the manual provisioning method. - [Edit your Entra ID integration](topics/integrate_entra_edit.md): In this topic, you will learn how to edit your Portnox™ Cloud integration with Entra ID. You will also learn about the meaning of additional options for this integration. - [Bypass multi-factor authentication in Entra ID](topics/integrate_entra_mfa.md): In this topic, you will learn how to whitelist the IP addresses of Portnox™ Cloud services in Microsoft Entra ID so that you can bypass multi-factor authentication \(MFA\) when accessing Entra ID services. - [Integrate with Google Workspace](topics/integrate_google.md): In this topic, you will learn how to integrate Portnox™ Cloud with Google Workspace. - [Edit your Google Workspace integration](topics/integrate_google_edit.md): In this topic, you will learn how to edit your Portnox™ Cloud integration with Google Workspace. You will also learn about the meaning of additional options for this integration. - [Integrate with Okta Wokforce Identity](topics/integrate_okta.md): In this topic, you will learn how to integrate Portnox™ Cloud with Okta Workforce Identity Cloud. - [Integrate with Okta Workforce Identity using LDAP](topics/integrate_okta_ldap.md): In this topic, you will continue Portnox™ Cloud integration with the Okta Workforce Identity Cloud using LDAP. - [Integrate with Active Directory](topics/integrate_ad.md): In this topic, you will learn how to integrate Portnox™ Cloud with a local Active Directory \(AD\) instance using the Portnox LDAP Broker. - [Edit your AD/OpenLDAP integration](topics/integrate_dis_edit.md): In this topic, you will learn how to edit your Portnox™ Cloud integration with local Active Directory or OpenLDAP. You will also learn about the meaning of additional options for this integration. - [Integrate with OpenLDAP](topics/integrate_openldap.md): In this topic, you will learn how to integrate Portnox™ Cloud with a local OpenLDAP instance. - [Edit your AD/OpenLDAP integration](topics/integrate_dis_edit_2.md): In this topic, you will learn how to edit your Portnox™ Cloud integration with local Active Directory or OpenLDAP. You will also learn about the meaning of additional options for this integration. ## Configuring accounts, groups, policies, and sites - Configuring accounts, groups, policies, and sites - [What are accounts, groups, policies, and sites?](topics/accounts_groups_policies.md): In this topic, you will learn what we mean by accounts, groups, policies, and sites in Portnox™ Cloud. - [How are devices added to Portnox Cloud?](topics/account_flow.md): In this topic, you will learn how devices are added to Portnox™ Cloud. - Configuring groups: In this collection of topics, you will learn how to configure groups in Portnox™ Cloud. - [Create a group](topics/group_create.md): In this topic, you will learn how to create a group in Portnox™ Cloud and configure network access layers. - [Edit and configure a group](topics/group_edit.md): In this topic, you will learn how to edit a group in Portnox™ Cloud and configure its advanced settings. - [Manage members of a group](topics/group_members.md): In this topic, you will learn how to automatically manage members of a group in Portnox™ Cloud based on groups and/or organizational units in Portnox Cloud and/or authentication repositories. - [The Default group](topics/group_default.md): In this topic, you will learn what is the Default group, how it differs from other groups, and how it functions in Portnox Cloud. - Configuring accounts: In this topic, you will learn how to configure accounts in Portnox™ Cloud. - [Create an account](topics/account_create.md): In this topic, you will learn how to create an account in Portnox™ Cloud. You can create accounts manually for IoT devices, external contractors, and more. - Configuring policies: In this collection of topics, you will learn how to configure policies in Portnox™ Cloud. - [Create or edit an access control policy](topics/policy_acp.md): In this topic, you will learn how to create and assign an access control policy in Portnox™ Cloud. - [Create a downloadable access control list \(dACL\) on a Cisco switch using the Policy Builder](topics/policy_acp_dacl_cisco.md): In this topic, you will learn how to create downloadable access lists \(dACLs\) on Cisco switches using the Portnox™ Cloud dACL Policy Builder. - [Create or edit a risk assessment policy](topics/policy_risk.md): In this topic, you will learn how to create and assign a risk assessment policy in Portnox™ Cloud. - [Configure risk based on the Intune integration](topics/policy_risk_intune.md): In this topic, you will learn how to set the Portnox™ Cloud risk policy attributes to assign risk scores based on the Microsoft Intune integration status and compliance. - [Create or edit a remediation policy](topics/policy_remediation.md): In this topic, you will learn how to create and assign a remediation policy in Portnox™ Cloud. - [Create or edit a custom RADIUS attribute policy](topics/policy_radius_custom.md): In this topic, you will learn how to create and assign a custom RADIUS attribute policy in Portnox™ Cloud. - [Create or edit a TACACS+ authorization policy](topics/policy_tacacs.md): In this topic, you will learn how to create and assign a TACACS+ authorization policy in Portnox™ Cloud. - [Create or edit a custom SAML attribute policy](topics/policy_saml.md): In this topic, you will learn how to create and assign a custom SAML attribute policy in Portnox™ Cloud. - [Assign policies to a group](topics/group_policies.md): In this topic, you will learn how to assign different types of policies to a selected group in Portnox™ Cloud. - Configuring sites: In this topic, you will learn how to configure a site in Portnox™ Cloud. - [Create a site](topics/site_create.md): In this topic, you will learn how to create a site in Portnox™ Cloud. - Configuring guest access: In this topic, you will learn how to configure a guest Wi-Fi network in Portnox™ Cloud. - [Configure a guest Wi-Fi network](topics/guest_network.md): In this topic, you will learn how to configure a guest Wi-Fi network in Portnox™ Cloud using a captive portal. ## Configuring NAS devices for RADIUS access - Configuring NAS devices for RADIUS access - [Configure Ethernet devices to work with Portnox Cloud](topics/nas_switches.md): In this collection of documents, you will find specific instructions for configuring Ethernet-based [NAS](glossary.md#) devices to access the Portnox™ Cloud RADIUS servers and provide [AAA](glossary.md#) services. - [Meraki](topics/nas_switches_meraki.md): In this topic, you will learn how to configure Cisco Meraki switch ports to work together with Portnox™ Cloud and 802.1X RADIUS authentication for wired Ethernet connections. - [Meraki Z3](topics/nas_switches_meraki_z3.md): In this topic, you will learn how to configure the Cisco Meraki Z3 Teleworker Gateway to work together with Portnox™ Cloud and 802.1X RADIUS authentication for wired Ethernet connections. - [Brocade](topics/nas_switches_brocade.md): In this topic, you will learn how to configure Brocade switches to work together with Portnox™ Cloud and 802.1X RADIUS authentication for wired Ethernet connections. - [Aruba](topics/nas_switches_aruba.md): In this topic, you will learn how to configure Aruba switches to work together with Portnox™ Cloud and 802.1X RADIUS authentication for wired Ethernet connections. - [Dell](topics/nas_switches_dell.md): In this topic, you will learn how to configure selected Dell switches to work together with Portnox™ Cloud and 802.1X RADIUS authentication for wired Ethernet connections. - [Juniper](topics/nas_switches_juniper.md): In this topic, you will learn how to configure Juniper switches to work together with Portnox™ Cloud and 802.1X RADIUS authentication for wired Ethernet connections. - [Cisco](topics/nas_switches_cisco.md): In this topic, you will learn how to configure Cisco switches to work together with Portnox™ Cloud and 802.1X RADIUS authentication for wired Ethernet connections. - [HP](topics/nas_switches_hp.md): In this topic, you will learn how to configure selected HP switches to work together with Portnox™ Cloud and 802.1X RADIUS authentication for wired Ethernet connections. - [Ruckus](topics/nas_switches_ruckus.md): In this topic, you will learn how to configure Ruckus switches to work together with Portnox™ Cloud and 802.1X RADIUS authentication for wired Ethernet connections. - [Arista](topics/nas_switches_arista.md): In this topic, you will learn how to configure Arista switches to work together with Portnox™ Cloud and 802.1X RADIUS authentication for wired Ethernet connections. - [Ubiquiti UniFi](topics/nas_switches_ubiquiti.md): In this topic, you will learn how to configure Ubiquiti UniFi switch ports to work together with Portnox™ Cloud and 802.1X RADIUS authentication for wired Ethernet connections. - [Fortinet](topics/nas_switches_fortinet.md): In this topic, you will learn how to configure Fortinet FortiSwitch switches to work together with Portnox™ Cloud and 802.1X RADIUS authentication for wired Ethernet connections. - [Configure wireless devices to work with Portnox Cloud](topics/nas_aps_employee_generic.md): In this collection of documents, you will find specific instructions for configuring wireless [NAS](glossary.md#) devices to access the Portnox™ Cloud RADIUS servers and provide [AAA](glossary.md#) services. - [Meraki](topics/nas_aps_employee_meraki.md): In this topic, you will learn how to configure Cisco Meraki access points to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections. - [Meraki Z3](topics/nas_aps_employee_meraki_z3.md): In this topic, you will learn how to configure the Cisco Meraki Z3 Teleworker Gateway to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections. - [Cisco](topics/nas_aps_employee_cisco.md): In this topic, you will learn how to configure a Cisco Wireless Controller to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections. - [Aruba](topics/nas_aps_employee_aruba.md): In this topic, you will learn how to configure Aruba wireless controllers to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections. - [Ruckus](topics/nas_aps_employee_ruckus.md): In this topic, you will learn how to configure Ruckus wireless controllers to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections. - [Fortinet](topics/nas_aps_employee_fortinet.md): In this topic, you will learn how to configure Fortinet wireless controllers to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections. - [Sophos](topics/nas_aps_employee_sophos.md): In this topic, you will learn how to configure the Sophos Central cloud to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections. - [Extreme Networks](topics/nas_aps_employee_extreme.md): In this topic, you will learn how to configure the Extreme Networks web interface to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections. - [Ubiquiti UniFi](topics/nas_aps_employee_ubiquiti.md): In this topic, you will learn how to configure Ubiquiti UniFi access points to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections. - [Mist](topics/nas_aps_employee_mist.md): In this topic, you will learn how to configure the Mist Cloud to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections. - [WatchGuard Firebox](topics/nas_aps_employee_watchguard_firebox.md): In this topic, you will learn how to configure the WatchGuard Firebox wireless controller to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections. - [WatchGuard Wi-Fi Cloud](topics/nas_aps_employee_watchguard.md): In this topic, you will learn how to configure the WatchGuard Wi-Fi Cloud to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections. - [Aerohive \(Extreme\)](topics/nas_aps_employee_aerohive.md): In this topic, you will learn how to configure legacy Aerohive devices using Extreme Cloud IQ \(previously HiveManager\) to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections. - [Configure wireless captive portals to work with Portnox Cloud](topics/nas_aps_guest.md): In this collection of documents, you will find specific instructions for configuring captive portals on wireless [NAS](glossary.md#) devices to work with the Portnox™ Cloud guest network. - [Meraki](topics/nas_aps_guest_meraki.md): In this topic, you will learn how to configure a Cisco Meraki access point to work together with the Portnox™ Cloud captive portal for guest user authentication. - [Cisco](topics/nas_aps_guest_cisco.md): In this topic, you will learn how to configure a Cisco Wireless Controller to work together with the Portnox™ Cloud captive portal for guest user authentication. - [Aruba](topics/nas_aps_guest_aruba.md): In this topic, you will learn how to configure Aruba wireless controllers to work together with the Portnox™ Cloud captive portal for guest user authentication. - [Ruckus](topics/nas_aps_guest_ruckus.md): In this topic, you will learn how to configure Ruckus ZoneDirector to work together with the Portnox™ Cloud captive portal for guest user authentication. - [Mist](topics/nas_aps_guest_mist.md): In this topic, you will learn how to configure Mist Cloud to work together with the Portnox™ Cloud captive portal for guest user authentication. - [Aerohive \(Extreme\)](topics/nas_aps_guest_aerohive.md): In this topic, you will learn how to configure legacy Aerohive devices using the Extreme Cloud IQ \(previously HiveManager\) to work together with the Portnox™ Cloud captive portal for guest user authentication. - [Extreme WiNG](topics/nas_aps_guest_wing.md): In this topic, you will learn how to configure Extreme WiNG to work together with the Portnox™ Cloud captive portal for guest user authentication. - [Fortinet](topics/nas_aps_guest_fortinet.md): In this topic, you will learn how to configure Fortinet controllers to work together with the Portnox™ Cloud captive portal for guest user authentication. - [Ubiquiti UniFi](topics/nas_aps_guest_unifi.md): In this topic, you will learn how to configure Ubiquiti UniFi controllers to work together with the Portnox™ Cloud captive portal for guest user authentication. - [Configure VPNs and other devices to work with Portnox Cloud](topics/nas_vpns.md): In this topic, you will learn how to configure a generic VPN device to work together with Portnox™ Cloud and 802.1X RADIUS authentication for VPN connections. You can use a similar configuration for other types of NAS devices such as firewalls. - [Meraki](topics/nas_vpns_meraki.md): In this topic, you will learn how to configure the Cisco Meraki Security Appliance to work together with Portnox™ Cloud and 802.1X RADIUS authentication for VPN connections. - [OpenVPN](topics/nas_vpns_openvpn.md): In this topic, you will set up the OpenVPN Access Server to use the Portnox Cloud RADIUS servers for authentication. - [WatchGuard](topics/nas_vpns_watchguard.md): In this topic, you will learn how to configure WatchGuard Fireware Mobile VPN to work together with Portnox™ Cloud and 802.1X RADIUS authentication for VPN connections. - [Fortinet](topics/nas_vpns_fortinet.md): In this topic, you will learn how to configure Fortinet FortiGate to work together with Portnox™ Cloud and 802.1X RADIUS authentication for VPN connections. - [Windows Server](topics/nas_vpns_windows.md): In this topic, you will set up Remote Access on a Windows Server to use the Portnox Cloud RADIUS servers for authentication with the Active Directory domain. - [Check Point](topics/nas_vpns_checkpoint.md): In this topic, you will learn how to configure the Check Point Smart Console to work together with Portnox™ Cloud and 802.1X RADIUS authentication for VPN connections. - [Palo Alto](topics/nas_vpns_paloalto.md): In this topic, you will learn how to configure Palo Alto GlobalProtect to work together with Portnox™ Cloud and 802.1X RADIUS authentication for VPN connections. - [Cisco](topics/nas_vpns_cisco.md): In this topic, you will learn how to configure Cisco ASA to work together with Portnox™ Cloud and 802.1X RADIUS authentication for VPN connections. ## Onboarding users and devices - Onboarding users and devices - [What is onboarding in Portnox Cloud?](topics/onboarding_about.md): In this topic, you will learn about the meaning of the term onboarding and the activities that are considered part of onboarding in Portnox™ Cloud. - Onboarding manually with credentials: In this collection of topics, you will learn how to onboard devices to Portnox™ Cloud manually using credentials. - [Windows + wired](topics/onboarding_credentials_windows_wired.md): In this topic, you will learn how to onboard using credentials, a Windows 10 computer, and a wired network managed by Portnox™ Cloud. - [Windows + Wi-Fi](topics/onboarding_credentials_windows_wifi.md): In this topic, you will learn how to onboard using credentials, a Windows 10 computer, and a Wi-Fi network managed by Portnox™ Cloud. - [macOS + wired/Wi-Fi](topics/onboarding_credentials_macos.md): In this topic, you will learn how to onboard using credentials, a macOS computer with Apple Configurator, and a network managed by Portnox™ Cloud. - [ChromeOS + Wi-Fi](topics/onboarding_credentials_chromeos_wifi.md): In this topic, you will learn how to onboard using credentials, a ChromeOS device such as a Chromebook, and a Wi-Fi network managed by Portnox™ Cloud. - [Linux + wired/Wi-Fi](topics/onboarding_credentials_linux_wired_wifi.md): In this topic, you will learn how to onboard using credentials, a Linux computer, and a network managed by Portnox™ Cloud. - [iOS + Wi-Fi](topics/onboarding_credentials_ios_wifi.md): In this topic, you will learn how to onboard using credentials, an iPhone with iOS, and a Wi-Fi network managed by Portnox™ Cloud. - [iOS + Wi-Fi \(iMazing\)](topics/onboarding_credentials_ios_wifi_imazing.md): In this topic, you will learn how to onboard using credentials, an iPhone with iOS, a Wi-Fi network managed by Portnox™ Cloud, and a custom profile created with the iMazing Profile Editor. - [Android + Wi-Fi](topics/onboarding_credentials_android_wifi.md): In this topic, you will learn how to onboard using credentials, an Android phone, and a Wi-Fi network managed by Portnox™ Cloud. - Onboarding with the self-onboarding portal: In this collection of topics, you will learn how to onboard devices to Portnox™ Cloud using the Portnox self-onboarding portal and credentials or certificates. - [Set up the self-onboarding portal](topics/onboarding_portal.md): In this topic, you will learn how to set up the Portnox™ Cloud self-onboarding portal for your users. - [Windows](topics/onboarding_self_windows.md): In this topic, you will learn how to onboard using the self-onboarding portal, a Windows 10 computer, and a wired or wireless network managed by Portnox™ Cloud. - [macOS](topics/onboarding_self_macos.md): In this topic, you will learn how to onboard using the self-onboarding portal, a macOS computer, and a wired or wireless network managed by Portnox™ Cloud. - [iOS](topics/onboarding_self_ios.md): In this topic, you will learn how to onboard using the self-onboarding portal, an iOS device such as an iPhone, and a wireless network managed by Portnox™ Cloud. - [Android](topics/onboarding_self_android.md): In this topic, you will learn how to onboard using the self-onboarding portal, an Android device, and a wireless network managed by Portnox™ Cloud. - [ChromeOS](topics/onboarding_self_chromeos.md): In this topic, you will learn how to onboard using the self-onboarding portal, a ChromeOS device such as a Chromebook, and a wireless network managed by Portnox™ Cloud. - [Linux](topics/onboarding_self_linux.md): In this topic, you will learn how to onboard using the self-onboarding portal, a Linux machine, and a wired or wireless network managed by Portnox™ Cloud. - [HP printer](topics/onboarding_self_hp.md): In this topic, you will learn how to onboard using the self-onboarding portal, a HP printer compatible with 802.1X, a Windows computer, the HP Smart application, and a Wi-Fi network managed by Portnox™ Cloud. - [IoT devices](topics/onboarding_self_iot.md): In this topic, you will learn how to onboard generic IoT devices to a network managed by Portnox™ Cloud using the self-onboarding portal. - Onboarding with Portnox Connect: In this collection of topics, you will learn how to onboard devices to Portnox™ Cloud using Portnox™ Connect. - [Set up Portnox Connect](topics/onboarding_connect.md): In this topic, you will learn how to make Portnox™ Connect available for your users. - [Windows](topics/onboarding_connect_windows.md): In this topic, you will learn how to onboard using Portnox Connect, a Windows computer, and a wired or wireless network managed by Portnox™ Cloud. - Onboarding with AgentP: In this collection of topics, you will learn how to onboard devices to Portnox™ Cloud using Portnox™ AgentP. - [Windows + Wi-Fi/wired](topics/onboarding_agentp_windows.md): In this topic, you will learn how to onboard using Portnox™ AgentP, a Windows 10 computer, and a Wi-Fi or wired network managed by Portnox™ Cloud. - [Windows multi-user](topics/onboarding_agentp_windows_multiuser.md): In this topic, you will learn how to onboard using Portnox™ AgentP, a Windows 10 computer with multiple users, and a Wi-Fi or wired network managed by Portnox™ Cloud. - [macOS + Wi-Fi/wired](topics/onboarding_agentp_macos.md): In this topic, you will learn how to onboard using Portnox™ AgentP, a macOS computer, and a Wi-Fi or wired network managed by Portnox™ Cloud. - [iOS + Wi-Fi](topics/onboarding_agentp_ios.md): In this topic, you will learn how to onboard using Portnox™ AgentP, an iPhone with iOS, and a Wi-Fi network managed by Portnox™ Cloud. - [Android + Wi-Fi](topics/onboarding_agentp_android.md): In this topic, you will learn how to onboard using Portnox™ AgentP, an Android phone, and a Wi-Fi network managed by Portnox™ Cloud. - [Linux + Wi-Fi/wired](topics/onboarding_agentp_linux.md): In this topic, you will learn how to onboard using Portnox™ AgentP, a Linux computer, and a Wi-Fi or wired network managed by Portnox™ Cloud. - [Linux headless](topics/onboarding_agentp_linux_headless.md): In this topic, you will learn how to install Portnox™ AgentP on a Linux headless device, such as a Linux server, and enroll it with Portnox Cloud. - Onboarding with MAC addresses: In this collection of topics, you will learn how to onboard devices to Portnox™ Cloud using MAC addresses. - [Create an account in Cloud](topics/onboarding_mac_manual.md): In this topic, you will learn how to onboard an IoT device to a network managed by Portnox™ Cloud by manually creating a new MAC-based account in Cloud. - [Create an account in the portal](topics/onboarding_mac_portal.md): In this topic, you will learn how to activate the MAC account registration portal and onboard an IoT device to a network managed by Portnox™ Cloud by creating a new MAC-based account in this portal. - [Create accounts automatically](topics/onboarding_mac_auto.md): In this topic, you will learn how to configure Portnox™ Cloud to create MAC-based accounts automatically for any new devices connecting to the network. - [MAC spoofing protection](topics/onboarding_mac_anti_spoofing.md): In this topic, you will learn how to turn on and use MAC address spoofing protection in Portnox™ Cloud. - Onboarding using endpoint management: In this collection of topics, you will learn how to onboard devices to Portnox™ Cloud using endpoint management solutions. - [SCEP + Intune + Windows](topics/onboarding_uem_intune_scep.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates to Windows devices via Microsoft Intune SCEP. - [SCEP + Intune + macOS](topics/onboarding_uem_intune_scep_macos.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates to macOS devices via Microsoft Intune SCEP. - [SCEP + Intune + iOS](topics/onboarding_uem_intune_scep_ios.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates to iOS devices via Microsoft Intune SCEP. - [SCEP + Intune + Android](topics/onboarding_uem_intune_scep_android.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates to Android devices via Microsoft Intune SCEP. - [SCEP + Google](topics/onboarding_uem_google_scep.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates via Google Workspace SCEP to manage Chromebook \(ChromeOS\) devices. - [SCEP + Jamf](topics/onboarding_uem_jamf_scep.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates via Jamf and SCEP to manage macOS devices. - [SCEP + Kandji](topics/onboarding_uem_kandji_scep.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates via Kandji and SCEP to manage macOS devices \(Wi-Fi only\). - [SCEP + Kandji \(iMazing\)](topics/onboarding_uem_kandji_scep_imazing.md): In this topic, you will learn how to deploy Portnox™ Cloud SCEP certificates via Kandji, SCEP, and iMazing Profile Editor to manage macOS devices \(Wi-Fi + Ethernet\). - [SCEP + Addigy \(iMazing\)](topics/onboarding_uem_addigy_scep.md): In this topic, you will learn how to deploy Portnox™ Cloud SCEP certificates via Addigy, SCEP, and iMazing Profile Editor to manage macOS devices. - [SCEP + WS1 + Windows](topics/onboarding_uem_wsone_scep.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates to Windows devices via Workspace ONE UEM and SCEP. - [SCEP + WS1 + macOS](topics/onboarding_uem_wsone_scep_macos.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates to macOS devices via Workspace ONE UEM and SCEP. - [SCEP + WS1 + iOS](topics/onboarding_uem_wsone_scep_ios.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates to iOS devices via Workspace ONE UEM and SCEP. - [SCEP + WS1 + Android](topics/onboarding_uem_wsone_scep_android.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates to Android devices via Workspace ONE UEM and SCEP. - [SCEP + SOTI + Windows](topics/onboarding_uem_soti_scep_windows.md): In this topic, you will learn how to deploy Portnox™ Cloud user certificates to Windows devices via SOTI MobiControl and SCEP. - [SCEP + SOTI + Android](topics/onboarding_uem_soti_scep_android.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates to Android devices via SOTI MobiControl and SCEP. - [SCEP + MaaS360 + Windows](topics/onboarding_uem_maas_scep.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates to Windows devices via MaaS 360 UEM and SCEP. - [SCEP + MaaS360 + iOS](topics/onboarding_uem_maas_scep_ios.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates to iOS devices via MaaS 360 UEM and SCEP. - [SCEP + MaaS360 + Android](topics/onboarding_uem_maas_scep_android.md): In this topic, you will learn how to deploy Portnox™ Cloud certificates to Android devices via MaaS 360 UEM and SCEP. - [SCEP + Certmonger \(Linux\)](topics/onboarding_uem_linux_scep.md): In this topic, you will learn how to obtain Portnox™ Cloud user certificates for managed Linux devices using Certmonger and SCEP. - [Own CA + Group Policy](topics/onboarding_uem_own.md): In this topic, you will learn how to create your own certificate authority in Windows Server, generate user certificates using Group Policy, and then use these certificates to onboard devices. - [AgentP + Group Policy](topics/onboarding_uem_agentp_gp.md): In this topic, you will learn how to deploy Portnox™ AgentP remotely on company devices using Group Policy. - [AgentP + Intune](topics/onboarding_uem_agentp_intune.md): In this topic, you will learn how to deploy Portnox™ AgentP on managed devices by using Intune. - [AgentP + Intune + macOS](topics/onboarding_uem_agentp_intune_macos.md): In this topic, you will learn how to deploy Portnox™ AgentP on managed macOS devices by using Intune and certificates managed by SCEP. - [AgentP + MCM \(SCCM\)](topics/onboarding_uem_agentp_mcm.md): In this topic, you will learn how to deploy Portnox™ AgentP on managed devices by using Microsoft Configuration Manager \(MCM\), previously known as Microsoft System Center Configuration Manager \(SCCM\). - [AgentP + Jamf](topics/onboarding_uem_agentp_jamf.md): In this topic, you will learn how to deploy Portnox™ AgentP on managed macOS devices by using Jamf if certificates are managed by SCEP. - [AgentP + Kandji](topics/onboarding_uem_agentp_kandji.md): In this topic, you will learn how to deploy Portnox™ AgentP on managed macOS devices by using Kandji. - [AgentP unattended/kiosk](topics/onboarding_uem_agentp_unattended.md): In this topic, you will learn how to run Portnox™ AgentP in unattended mode or kiosk mode. - Other onboarding methods: In this collection of topics, you will learn about other onboarding methods for unique situations. - [Linux + Certmonger](topics/onboarding_certificates_linux_certmonger.md): In this topic, you will learn how to onboard using certificates, the Certmonger service, a Linux computer, and a network managed by Portnox™ Cloud. - [Own root CA](topics/onboarding_certificates_own.md): In this topic, you will learn how to onboard devices using device certificates signed by your own root certificate authority. - Monitoring mode: In this collection of topics, you will learn how to use the monitoring mode to safely onboard devices without risking the loss of network access. - [About the monitoring mode](topics/monitoring_about.md): In this topic, you will learn what is the Portnox™ Cloud monitoring mode, how it works, and how to use it effectively. - [Turn on monitoring mode for a NAS device](topics/monitoring_nas.md): In this topic, you will learn how to turn on monitoring mode for a single NAS device that is already registered in Portnox™ Cloud. - [Turn on the global monitoring mode](topics/monitoring_global.md): In this topic, you will learn how to turn on the global monitoring mode, which will cause all newly connecting NAS devices to be set to monitoring mode. ## Integrating with other platforms - Integrating with other platforms - [Integrating with SIEM platforms](topics/integrate_siem.md): In this collection of topics, you will learn how to integrate Portnox™ Cloud with different security information and event management \(SIEM\) platforms. - [Integrate with Microsoft Sentinel](topics/integrate_sentinel.md): In this topic, you will learn how to send Portnox™ Cloud alerts to the Microsoft Sentinel SIEM solution. - [Integrate with Rapid7 insightIDR](topics/integrate_insightidr.md): In this topic, you will learn how to send Portnox™ Cloud alerts to the Rapid7 insightIDR SIEM solution. - [Integrate with Datadog](topics/integrate_datadog.md): In this topic, you will learn how to send Portnox™ Cloud alerts to the Datadog SIEM solution. - [Integrate with Datadog using a syslog forwarder](topics/integrate_datadog_syslog.md): In this topic, you will learn how to send Portnox™ Cloud alerts to the Datadog SIEM solution using a syslog forwarder. - [Integrate with Datadog using a syslog forwarder and TLS](topics/integrate_datadog_tls.md): In this topic, you will learn how to send Portnox™ Cloud alerts to the Datadog SIEM solution using a syslog forwarder with TLS for increased security. - [Integrate with Sumo Logic](topics/integrate_sumologic.md): In this topic, you will learn how to send Portnox™ Cloud alerts to the Sumo Logic SIEM solution. - [Integrate with Splunk](topics/integrate_splunk.md): In this topic, you will learn how to send Portnox™ Cloud alerts to the Splunk Cloud. - [Integrate with Google SecOps](topics/integrate_gso.md): In this topic, you will learn how to send Portnox™ Cloud alerts to Google SecOps. - [Integrate with Loggly](topics/integrate_loggly.md): In this topic, you will learn how to send Portnox™ Cloud alerts to the Loggly SIEM solution. - [Integrate with Papertrail](topics/integrate_papertrail.md): In this topic, you will learn how to send Portnox™ Cloud alerts to the Papertrail SIEM solution. - [Integrate with NXLog](topics/integrate_nxlog.md): In this topic, you will learn how to send Portnox™ Cloud alerts to an on-premises NXLog Community Edition instance. - [Integrate with Kiwi](topics/integrate_kiwi.md): In this topic, you will learn how to send Portnox™ Cloud alerts to on-premises SolarWinds Kiwi Syslog Server. - [Integrate with Microsoft Intune](topics/integrate_intune.md): In this topic, you will learn how to set up the integration between Portnox™ Cloud and Microsoft Intune. - [Integrate with Intune using multiple applications](topics/integrate_intune_multiple.md): In this topic, you will learn how to set up the integration between Portnox™ Cloud and Microsoft Intune using multiple applications. - [Integrate with Jamf](topics/integrate_jamf.md): In this topic, you will learn how to set up the integration between Portnox™ Cloud and Jamf. - [Integrate with Absolute Secure Endpoint](topics/integrate_absolute.md): In this topic, you will learn how to integrate Portnox™ Cloud with Absolute Secure Endpoint to provide device security information for risk assessment policies. - [Integrate with CrowdStrike Falcon](topics/integrate_crowdstrike.md): In this topic, you will learn how to set up the integration between Portnox™ Cloud and CrowdStrike Falcon. - [Integrate with SentinelOne](topics/integrate_sentinelone.md): In this topic, you will learn how to set up the integration between Portnox™ Cloud and SentinelOne. - [Integrate with eduroam](topics/integrate_eduroam.md): In this topic, you will learn how to integrate Portnox™ Cloud with the eduroam service. - [Other integrations](topics/other_integrations.md): In this topic, you will find links to documents describing other integrations between Portnox™ Cloud and third-party products. - [Authentication – JumpCloud](topics/integrate_jumpcloud.md): In this topic, you will learn how to integrate Portnox™ Cloud with JumpCloud. - [RADIUS MFA – Okta](topics/integrate_okta_radius_mfa.md): In this topic, you will learn how to enable multi-factor authentication for RADIUS-based connections through Okta. - [RADIUS local – Nutanix](topics/integrate_nutanix.md): In this topic, you will learn how to integrate Portnox™ Cloud with Nutanix. ## Managing TACACS+ services - Managing TACACS+ services - [How does the Portnox Cloud TACACS+ service work?](topics/tacacs_about.md): In this topic, you will learn how the Portnox™ Cloud TACACS+ service works. - [Set up a local TACACS+ server using a virtual machine](topics/tacacs_local_vm.md): In this topic, you will learn how to install and run local TACACS+ servers that work together with Portnox™ Cloud using virtual machines. - [Run the local TACACS+ server in Microsoft Hyper-V](topics/tacacs_local_hyperv.md): In this topic, you will learn how to install and configure the Portnox™ Cloud local TACACS+ server in the Microsoft Hyper-V hypervisor. - [Run the local TACACS+ server in VMware vSphere \(ESXi\)](topics/tacacs_local_vsphere.md): In this topic, you will learn how to install and configure the Portnox™ Cloud local TACACS+ server in the VMware vSphere ESXi hypervisor. - [Run the local TACACS+ server in VMware Workstation](topics/tacacs_local_vmware.md): In this topic, you will learn how to install and configure the Portnox™ Cloud local TACACS+ server in the VMware Workstation hypervisor. - [Run the local TACACS+ server in Oracle VirtualBox](topics/tacacs_local_virtualbox.md): In this topic, you will learn how to install and configure the Portnox™ Cloud local TACACS+ server in the Oracle VirtualBox hypervisor. - [Run the local TACACS+ server in a container](topics/tacacs_local_docker.md): In this topic, you will learn how to deploy the Portnox™ Cloud local TACACS+ server using Docker containers. - [Deploy the local TACACS+ server container in Microsoft Azure](topics/tacacs_local_azure.md): In this topic, you will learn how to deploy the Portnox™ Cloud local TACACS+ server container in Microsoft Azure using Azure Container Instances. - [Deploy the local TACACS+ server container in Amazon Web Services \(AWS\)](topics/tacacs_local_aws.md): In this topic, you will learn how to deploy the Portnox™ Cloud local TACACS+ server container in Amazon Web Services \(AWS\) using AWS Fargate. - [Deploy the local TACACS+ server container in Google Cloud Platform \(GCP\)](topics/tacacs_local_gcp.md): In this topic, you will learn how to deploy the Portnox™ Cloud local TACACS+ server container in Google Cloud Platform \(GCP\) using the Google Compute Engine \(GCE\). - [Deploy the local TACACS+ server container using Docker on Linux](topics/tacacs_local_linux.md): In this topic, you will learn how to deploy the Portnox™ Cloud local TACACS+ server container using Docker on a local Linux machine \(physical or virtual\). - [Deploy the local TACACS+ server container using Docker Desktop on Windows](topics/tacacs_local_windows.md): In this topic, you will learn how to deploy the Portnox™ Cloud local TACACS+ server container using Docker Desktop on a local Windows machine \(physical or virtual\). - [Configure NAS devices to access the TACACS+ server](topics/tacacs_nas.md): In this topic, you will find tips on how to configure your NAS devices to access the Portnox™ Cloud local TACACS+ server. ## Managing Zero Trust Network Access - Managing Zero Trust Network Access - [What is Portnox Zero Trust Network Access \(ZTNA\) and how does it work?](topics/zero_trust_network_access.md): In this topic, you will learn about Portnox™ Zero Trust Network Access \(ZTNA\) and how it provides secure access to SSO web applications and to resources hosted on-premises or in private cloud environments. - ZTNA for SSO-enabled web applications: In this collection of topics, you will learn how to configure third-party identity providers and SSO-enabled web applications to work with Portnox™ ZTNA. - [Identity provider integration](topics/ztna_identity_general.md): In this topic, you will find general instructions on how to add an identity provider that will be used by Portnox™ ZTNA for SSO-enabled web applications. - [Microsoft Entra ID \(SAML\)](topics/ztna_identity_entraid.md): In this topic, you will find instructions on how to add Microsoft Entra ID as a SAML identity provider for Portnox™ Zero Trust Network Access. - [Microsoft Entra ID \(OIDC\)](topics/ztna_identity_entraid_oidc.md): In this topic, you will find instructions on how to add Microsoft Entra ID as an OIDC identity provider for Portnox™ Zero Trust Network Access. - [Google Workspace \(SAML\)](topics/ztna_identity_googlews.md): In this topic, you will find instructions on how to add Google Workspace as a SAML identity provider for Portnox™ Zero Trust Network Access. - [Google Cloud \(OIDC\)](topics/ztna_identity_google_oidc.md): In this topic, you will find instructions on how to add Google Cloud as an OIDC identity provider for Portnox™ Zero Trust Network Access. - [Okta Platform \(SAML\)](topics/ztna_identity_okta.md): In this topic, you will find instructions on how to add Okta Platform as a SAML identity provider for Portnox™ Zero Trust Network Access. - [Okta Platform \(OIDC\)](topics/ztna_identity_okta_oidc.md): In this topic, you will find instructions on how to add Okta Platform as an OIDC identity provider for Portnox™ Zero Trust Network Access. - [Okta Platform \(factor\)](topics/ztna_identity_okta_factor.md): In this topic, you will find instructions on how to add Portnox™ Zero Trust Network Access to the Okta Platform as an authentication factor. - [Application integration](topics/ztna_application_general.md): In this topic, you will find general instructions on how to integrate an SSO web application with Portnox™ Zero Trust Network Access. - [Absolute](topics/ztna_application_absolute.md): In this topic, you will find general instructions on how to integrate [Absolute](https://www.absolute.com/) with Portnox™ Zero Trust Network Access. - [AlertOps](topics/ztna_application_alertops.md): In this topic, you will find general instructions on how to integrate [AlertOps](https://alertops.com/) with Portnox™ Zero Trust Network Access. - [Asana](topics/ztna_application_asana.md): In this topic, you will find general instructions on how to integrate [Asana](https://app.asana.com/) with Portnox™ Zero Trust Network Access. - [Atlassian Access](topics/ztna_application_atlassian.md): In this topic, you will find general instructions on how to integrate [Atlassian](https://www.atlassian.com/) Access products with Portnox™ Zero Trust Network Access. - [BambooHR](topics/ztna_application_bamboohr.md): In this topic, you will find general instructions on how to integrate [BambooHR](https://www.bamboohr.com/) with Portnox™ Zero Trust Network Access. - [BILL](topics/ztna_application_bill.md): In this topic, you will find general instructions on how to integrate [BILL](https://www.bill.com/) with Portnox™ Zero Trust Network Access. - [Canva](topics/ztna_application_canva.md): In this topic, you will find general instructions on how to integrate [Canva](https://www.canva.com/) with Portnox™ Zero Trust Network Access. - [Datadog](topics/ztna_application_datadog.md): In this topic, you will find general instructions on how to integrate [Datadog](https://www.datadoghq.com/) with Portnox™ Zero Trust Network Access. - [DigiCert](topics/ztna_application_digicert.md): In this topic, you will find general instructions on how to integrate [DigiCert](https://www.digicert.com/) with Portnox™ Zero Trust Network Access. - [Dropbox](topics/ztna_application_dropbox.md): In this topic, you will find general instructions on how to integrate [Dropbox](https://www.dropbox.com/) with Portnox™ Zero Trust Network Access. - [Egnyte](topics/ztna_application_egnyte.md): In this topic, you will find general instructions on how to integrate [Egnyte](https://www.egnyte.com/) with Portnox™ Zero Trust Network Access. - [Entra ID](topics/ztna_application_entraid.md): In this topic, you will find instructions on how to enable and configure certificate-based access \(CBA\) in Microsoft Entra ID and use Zero Trust Network Access certificates managed by Portnox AgentP for safe and quick Entra ID authentication. - [Expensify](topics/ztna_application_expensify.md): In this topic, you will find general instructions on how to integrate [Expensify](https://www.expensify.com/) with Portnox™ Zero Trust Network Access. - [Figma](topics/ztna_application_figma.md): In this topic, you will find general instructions on how to integrate [Figma](https://www.figma.com/) with Portnox™ Zero Trust Network Access. - [Freshdesk](topics/ztna_application_freshdesk.md): In this topic, you will find general instructions on how to integrate [Freshdesk](https://www.freshworks.com/freshdesk/) with Portnox™ Zero Trust Network Access. - [GitHub](topics/ztna_application_github.md): In this topic, you will find general instructions on how to integrate [GitHub](https://github.com/) with Portnox™ Zero Trust Network Access. - [GitLab](topics/ztna_application_gitlab.md): In this topic, you will find general instructions on how to integrate [GitLab](https://about.gitlab.com/) with Portnox™ Zero Trust Network Access. - [Gong](topics/ztna_application_gong.md): In this topic, you will find general instructions on how to integrate [Gong](https://www.gong.io/) with Portnox™ Zero Trust Network Access. - [GoTo](topics/ztna_application_goto.md): In this topic, you will find general instructions on how to integrate [GoTo](https://www.goto.com/) applications with Portnox™ Zero Trust Network Access. - [Google Workspace](topics/ztna_application_google_workspace.md): In this topic, you will find general instructions on how to integrate [Google Workspace](https://workspace.google.com/) with Portnox™ Zero Trust Network Access. - [Grammarly](topics/ztna_application_grammarly.md): In this topic, you will find general instructions on how to integrate [Grammarly](https://www.grammarly.com/) with Portnox™ Zero Trust Network Access. - [HiBob](topics/ztna_application_hibob.md): In this topic, you will find general instructions on how to integrate [HiBob](https://www.hibob.com/) with Portnox™ Zero Trust Network Access. - [HubSpot](topics/ztna_application_hubspot.md): In this topic, you will find general instructions on how to integrate [HubSpot](https://www.hubspot.com/) with Portnox™ Zero Trust Network Access. - [Huntress](topics/ztna_application_huntress.md): In this topic, you will find general instructions on how to integrate [Huntress](https://www.huntress.com/) with Portnox™ Zero Trust Network Access. - [Jamf Cloud](topics/ztna_application_jamf.md): In this topic, you will find general instructions on how to integrate [Jamf Cloud](https://www.jamf.com/) with Portnox™ Zero Trust Network Access. - [Jenkins \(on-premises\)](topics/ztna_application_jenkins.md): In this topic, you will find general instructions on how to integrate [Jenkins](https://www.jenkins.io/) installed on-premises with Portnox™ Zero Trust Network Access. - [Kandji](topics/ztna_application_kandji.md): In this topic, you will find general instructions on how to integrate [Kandji](https://www.kandji.io/) with Portnox™ Zero Trust Network Access. - [Logitech Sync](topics/ztna_application_logitech.md): In this topic, you will find general instructions on how to integrate [Logitech Sync](https://sync.logitech.com/) with Portnox™ Zero Trust Network Access. - [Lucidchart](topics/ztna_application_lucidchart.md): In this topic, you will find general instructions on how to integrate [Lucidchart](https://www.lucidchart.com/) with Portnox™ Zero Trust Network Access. - [Miro](topics/ztna_application_miro.md): In this topic, you will find general instructions on how to integrate [Miro](https://miro.com/) with Portnox™ Zero Trust Network Access. - [OneLogin](topics/ztna_application_onelogin.md): In this topic, you will find general instructions on how to integrate [OneLogin](https://www.onelogin.com/) with Portnox™ Zero Trust Network Access. - [Outreach](topics/ztna_application_outreach.md): In this topic, you will find general instructions on how to integrate [Outreach](https://www.outreach.io/) with Portnox™ Zero Trust Network Access. - [PagerDuty](topics/ztna_application_pagerduty.md): In this topic, you will find general instructions on how to integrate [PagerDuty](https://pagerduty.com/) with Portnox™ Zero Trust Network Access. - [Paylocity](topics/ztna_application_paylocity.md): In this topic, you will find general instructions on how to integrate [Paylocity](https://www.paylocity.com/) with Portnox™ Zero Trust Network Access. - [Pinpoint](topics/ztna_application_pinpoint.md): In this topic, you will find general instructions on how to integrate [Pinpoint](https://www.pinpointhq.com/) with Portnox™ Zero Trust Network Access. - [Planhat](topics/ztna_application_planhat.md): In this topic, you will find general instructions on how to integrate [Planhat](https://www.planhat.com/) with Portnox™ Zero Trust Network Access. - [Remote](topics/ztna_application_remote.md): In this topic, you will find general instructions on how to integrate [Remote](https://remote.com/) with Portnox™ Zero Trust Network Access. - [Salesforce](topics/ztna_application_salesforce.md): In this topic, you will find general instructions on how to integrate [Salesforce](https://www.salesforce.com/) with Portnox™ Zero Trust Network Access. - [Slack](topics/ztna_application_slack.md): In this topic, you will find general instructions on how to integrate [Slack](https://slack.com/) with Portnox™ Zero Trust Network Access. - [SOTI ONE](topics/ztna_application_soti.md): In this topic, you will find general instructions on how to integrate [SOTI ONE](https://soti.net/products/soti-one-platform/) with Portnox™ Zero Trust Network Access. - [Splunk Cloud](topics/ztna_application_splunk.md): In this topic, you will find general instructions on how to integrate [Splunk Cloud](https://www.splunk.com/) with Portnox™ Zero Trust Network Access. - [SolarWinds Observability](topics/ztna_application_swo.md): In this topic, you will find general instructions on how to integrate [SolarWinds Observability](https://www.solarwinds.com/solarwinds-observability) with Portnox™ Zero Trust Network Access. - [Synology NAS](topics/ztna_application_synology.md): In this topic, you will find general instructions on how to integrate a [Synology](https://www.synology.com/) NAS with Portnox™ Zero Trust Network Access. - [Tableau](topics/ztna_application_tableau.md): In this topic, you will find general instructions on how to integrate [Tableau](https://www.tableau.com/) with Portnox™ Zero Trust Network Access. - [Tailscale](topics/ztna_application_tailscale.md): In this topic, you will find general instructions on how to integrate [Tailscale](https://tailscale.com/) with Portnox™ Zero Trust Network Access. - [WalkMe](topics/ztna_application_walkme.md): In this topic, you will find general instructions on how to integrate [WalkMe](https://www.walkme.com/) with Portnox™ Zero Trust Network Access. - [WordPress](topics/ztna_application_wordpress.md): In this topic, you will find general instructions on how to integrate [WordPress](https://wordpress.com/) with Portnox™ Zero Trust Network Access using the miniOrange SAML plugin. - [Wrike](topics/ztna_application_wrike.md): In this topic, you will find general instructions on how to integrate [Wrike](https://wrike.com/) with Portnox™ Zero Trust Network Access. - [Zendesk](topics/ztna_application_zendesk.md): In this topic, you will find general instructions on how to integrate [Zendesk](https://www.zendesk.com/) with Portnox™ Zero Trust Network Access. - [Zoho](topics/ztna_application_zoho.md): In this topic, you will find general instructions on how to integrate [Zoho](https://www.zoho.com/) with Portnox™ Zero Trust Network Access. - [Zoom](topics/ztna_application_zoom.md): In this topic, you will find general instructions on how to integrate [Zoom](https://zoom.us/) with Portnox™ Zero Trust Network Access. - [Entra ID EAM integration](topics/ztna_eam.md): In this topic, you will find instructions on how to add Portnox™ Zero Trust Network Access as an external authentication method \(EAM\) in Microsoft Entra ID. - ZTNA for hosted resources: In this collection of topics, you will learn how to use Portnox™ ZTNA to control access to hosted resources such as on-premises applications. - [HTTPS resources + Linux Docker](topics/ztna_hosted_linux.md): In this topic, you will learn how to configure Portnox™ ZTNA to allow your remote users to access your private resources hosted on-premises, by using a Docker container in an on-premises machine with Linux. - [Console resources + Linux Docker](topics/ztna_console_linux.md): In this topic, you will learn how to configure Portnox™ ZTNA to allow your remote users to access your private console resources hosted on-premises, by using a Docker container in an on-premises machine with Linux. - [HTTPS resources + Windows Docker](topics/ztna_hosted_windows.md): In this topic, you will learn how to configure Portnox™ ZTNA to allow your remote users to access your private resources hosted on-premises, by using a Docker container in an on-premises machine with Windows. - [Console resources + Windows Docker](topics/ztna_console_windows.md): In this topic, you will learn how to configure Portnox™ ZTNA to allow your remote users to access your private console resources hosted on-premises, by using a Docker container in an on-premises machine with Windows. - [HTTPS resources + Azure Docker](topics/ztna_hosted_azure.md): In this topic, you will learn how to configure Portnox™ Zero Trust Network Access to allow your users to access your private web applications hosted in Microsoft Azure and accessible within an Azure private network, by using a Docker container in an Azure container instance. - [Console resources + Azure Docker](topics/ztna_console_azure.md): In this topic, you will learn how to configure Portnox™ Zero Trust Network Access to allow your users to access your private console resources hosted in Microsoft Azure and accessible within an Azure private network, by using a Docker container in an Azure container instance. - [The Secure Access Portal for Portnox ZTNA](topics/ztna_portal.md): In this topic, you will learn about the Secure Access Portal, which provides a single place to access all applications and resources configured for access through Portnox ZTNA. - Tips and tricks for ZTNA: In this collection of topics, you will find any additional information about Portnox ZTNA. - [Configure user browsers to automatically select the ZTNA certificate](topics/ztna_certificate_autoselection.md): In this topic, you will learn how to configure user browsers on Windows and macOS devices using UEM solutions \(Microsoft Intune and Jamf\) so that users are not prompted to select a certificate when accessing resources protected by Portnox™ ZTNA. ## Alerts, logging, and reporting - Alerts, logging, and reporting - [Portnox Cloud alerts](topics/alerts.md): In this topic, you will learn what are alerts in Portnox™ Cloud, where to find them, and how to use them effectively. - [List of alerts](topics/alerts_list.md): In this topic, you will find the full list of Portnox Cloud alerts that can appear on the Alerts screen along with explanations that may help you troubleshoot. - [Alert merging](topics/alerts_merging.md): In this topic, you will find out when Portnox Cloud alerts are merged together into a single compound alert. - [Alert format/content](topics/alerts_information.md): In this topic, you will learn what alert information is sent to integrated SIEM solutions and in what format. - [AAA Logs](topics/alerts_aaa.md): In this topic, you will learn what are AAA logs in Portnox™ Cloud, where to find them, and how to use them effectively. - [Packet capture service](topics/alerts_pcap.md): In this topic, you will learn how to use the Portnox™ Cloud packet capture service to troubleshoot network problems. - [Reporting service](topics/alerts_reports.md): In this topic, you will learn what is the Portnox™ Cloud reporting service and how to download and/or schedule different types of reports. ## Portnox tools and applications - Portnox tools and applications - AgentP: In this collection of topics, you will learn about Portnox™ AgentP, a lightweight agent for end-user devices. - [What is Portnox AgentP?](topics/agentp.md): In this topic, you will learn what is the Portnox™ AgentP software and how it works. - [AgentP working and installation modes](topics/agentp_modes.md): In this topic, you will learn about the three working modes and the two installation modes of AgentP. - [AgentP and certificates](topics/agentp_certificates.md): In this topic, you will learn what certificates AgentP installs on Windows computers in its different operating modes. - [Configure AgentP options](topics/agentp_configure.md): In this topic, you will learn how to configure options available to users of Portnox™ AgentP. - [AgentP configuration/installation options](topics/agentp_options.md): In this topic, you will learn all options available to configure Portnox™ AgentP. - Portnox Connect: In this collection of topics, you will learn about Portnox™ Connect, a zero-footprint configuration utility for BYOD devices. - [What is Portnox Connect?](topics/connect.md): In this topic, you will learn what is the Portnox™ Connect software and how it works. - LDAP Broker: In this collection of topics, you will learn about Portnox™ LDAP Broker, a software that allows Portnox Cloud to work together with on-premises repositories. - [LDAP Broker](topics/ldapbroker.md): In this topic, you will learn what is the Portnox™ LDAP Broker software and how it works. - VMs and Docker containers: In this collection of topics, you will learn about several Portnox™ virtual machines and Docker containers that Extend Portnox Cloud services to on-premises environments and private clouds. - [Local RADIUS](topics/radius_local_server.md): In this topic, you will learn what is the Portnox™ local RADIUS server software and how it works. - [Local TACACS+](topics/tacacs_local_server.md): In this topic, you will learn what is the Portnox™ local TACACS+ server software and how it works. - [Automatic updates for all Docker containers](topics/docker_autoupdate.md): In this topic, you will learn about the Portnox Docker container that automatically updates all other Portnox Docker containers. - Portnox Cloud API - [Portnox Cloud REST API](topics/api.md): In this topic, you will find introductory information about the Portnox Cloud REST API, the available API functions, and their most common uses. - [Testing the Portnox Cloud REST API](topics/api_testing.md): In this topic, you will learn how to test the Portnox™ Cloud REST API by using the interface in the Portnox Cloud web portal. - Free tools, utilities, and scripts - [Portnox Enrollment Portal](topics/script_portnoxenrollmentportal.md): In this topic, you will learn about the Portnox Enrollment Portal, an internal web application that allows corporate users to obtain Portnox Cloud accounts for their personal devices \(BYOD\) without requiring manual intervention from IT. ## Best practices - Best practices - [Portnox Cloud best practices](topics/recommendations_best_practices.md): In this topic, you will find technical suggestions prepared by Portnox staff to help you make informed decisions about your Portnox Cloud deployment. - [Preventive measures](topics/recommendations_preventive.md): In this topic, you will learn what preventive steps you can take to avoid disruption of your services secured by Portnox™ Cloud, if there are faults or outages. - [Reactive measures](topics/recommendations_reactive.md): In this topic, you will learn what reactive steps you can take to maintain partial access to your services secured by Portnox™ Cloud in case of a fault or an outage. - [Troubleshooting NAC](topics/recommendations_troubleshooting_nac.md): In this topic, you will learn how to troubleshoot common issues with network access control, identify potential root causes, and review key areas to investigate before submitting a support ticket. - [IoT onboarding](topics/recommendations_mac_onboarding.md): In this topic, you will find a suggested process for onboarding IoT devices, when their full inventory is not known. - [Offboarding](topics/recommendations_offboarding.md): In this topic, you will find suggestions for safe offboarding from Portnox Cloud if you no longer want to use Cloud services and, instead, go back to an insecure network, or use a different product/service. ## Knowledge base - Knowledge base - Security/Architecture - [Security architecture and principles](topics/kb_security_principles.md): In this topic, you will learn about the Portnox™ Cloud security principles and how they apply to every layer of the Portnox Cloud architecture. - [Availability and reliability of Cloud](topics/kb_availability.md): In this topic, you will learn about the availability and reliability of the Portnox Cloud™ services. - [Cloud maintenance and updates](topics/kb_maintenance.md): In this topic, you will find the answers to common questions about Portnox Cloud maintenance and updates. - [Portnox Cloud shared responsibility model \(SRM\)](topics/kb_srm.md): This topic outlines the shared responsibility model \(SRM\) for Portnox Cloud SaaS tenants. It clarifies which security and operational tasks are owned by Portnox, the customer, or shared between both parties. - [Blast-RADIUS vulnerability](topics/kb_blastradius.md): In this topic, you will find information about the Blast-RADIUS vulnerability and its impact on Portnox Cloud users. - [New back-end IPs](topics/kb_ip_ranges.md): In this topic, you will learn about the new Portnox Cloud back-end IP ranges and where to add them to keep your Portnox Cloud services running without disruption. - Certificates - [Types of certificates](topics/kb_certificates.md): In this topic, you will learn about the different types of certificates that are used by Portnox™ Cloud to secure communications. - [Certificate revocation](topics/kb_certificate_revocation.md): In this topic, you will learn how Portnox Cloud handles certificate revocation for user and device certificates. - Licensing - [License consumption](topics/kb_licensing.md): In this topic, you will find information about when Portnox Cloud consumes a license for devices. - [Device retention periods](topics/kb_retention.md): In this topic, you will learn the retention periods for devices in Portnox™ Cloud. - [Intune interface matching](topics/kb_licensing_intune.md): In this topic, you will learn how to use session details to check if two network interfaces belong to the same Intune-managed device, and therefore are treated as a single device and consume only one license. - Portnox Cloud portal - [Troubleshooting portal issues](topics/kb_troubleshooting_portal.md): In this topic, you will learn how to address the most common issues when using the Portnox™ Cloud portal [https://cloud.portnox.com](https://cloud.portnox.com). - [SMS messages not arriving](topics/kb_sms_not_arriving.md): In this topic, you will find information about why SMS messages for multi-factor authentication may not be arriving to the user, if the user is located in the United Kingdom, Australia, or Singapore. - Network access - [Troubleshooting network issues](topics/kb_troubleshooting_network.md): In this topic, you will learn how to address the most common issues when connecting to networks protected by Portnox™ Cloud. - [MAC address randomization](topics/kb_mac_address_randomization.md): In this topic, you will learn why MAC address randomization causes issues in Portnox Cloud™ and how to turn it off manually. - [Fast reconnect](topics/kb_fast_reconnect.md): In this topic, you will learn how to configure Wi-Fi network adapters on client devices to support the fast reconnect function of Portnox Cloud RADIUS servers – also known as EAP session resumption – if you previously disabled it or want to verify that it is enabled. - Onboarding - [Troubleshooting onboarding issues](topics/kb_troubleshooting_onboarding.md): In this topic, you will learn how to address the most common issues when onboarding devices onto a network managed by Portnox™ Cloud. - Cloud RADIUS - [Testing Cloud RADIUS connectivity](topics/kb_radius_connectivity.md): In this topic, you will learn what you can do to test the connectivity between your devices and Portnox™ Cloud RADIUS servers. - [Packet captures](topics/kb_packet_capture.md): In this topic, you will learn what kind of packet captures Portnox™ support needs to troubleshoot your issues. - [Certificate fragmentation issues](topics/kb_fragmentation.md): In this topic, you will learn how to address fragmentation issues when onboarding devices onto a network managed by Portnox™ Cloud using certificates. - [EAP methods and their security](topics/kb_eap_methods.md): In this topic, you will learn more about the EAP methods used by Portnox™ Cloud, authentication repositories, and operating systems. - [WPA Enterprise Wi‑Fi security](topics/kb_wpa_enterprise.md): In this topic, you will learn about WPA Enterprise wireless security protocols, how they relate to RADIUS, and how they are supported by Portnox™ Cloud. - Local RADIUS/TACACS+ instances - [Troubleshooting using SSH](topics/kb_troubleshooting_ssh.md): In this topic, you will learn how to troubleshoot problems with the operation of the local RADIUS or local TACACS+ instance in a virtual machine by using the PuTTY application, the SSH protocol, and Linux shell commands. - [Local RADIUS: Performance monitoring](topics/kb_radius_monitoring.md): In this topic, you will find suggestions on monitoring the performance of the local RADIUS instance in a virtual machine. Such monitoring will require third-party tools. - [Monitoring with PRTG](topics/kb_radius_monitoring_prtg.md): In this topic, you will learn how to monitor your local RADIUS virtual machine using the PRTG Network Monitor. - [Local RADIUS: Firewall configuration](topics/kb_radius_local_firewall.md): In this topic, you will learn how to configure your firewall to make sure that the local RADIUS instance can communicate with the Cloud. - [Local RADIUS: Load balancing](topics/kb_radius_load_balancing.md): Use this task to configure local RADIUS and Portnox Cloud groups for RADIUS load balancing, using Citrix NetScaler as an example. - [Azure ACI: Local RADIUS with stable IPs](topics/kb_radius_container_instance_ips.md): In this topic, you will learn how to deploy local RADIUS and TACACS+ container instances in Microsoft Azure while ensuring stable IP addresses for NAS device configuration. - [Azure ACI: Local RADIUS dormant](topics/kb_radius_container_instance_dormant.md): In this topic, you will find guidance to diagnose and resolve a situation where the Portnox™ Local RADIUS container on an Azure container instance \(ACI\) enters a dormant state. This problem is usually caused by DNS or networking issues within Azure or your network environment. - [Local RADIUS: open-vm-tools](topics/kb_radius_vm_tools.md): In this topic, you will learn how to install and run VMware’s open-vm-tools on a VMware virtual machine \(VM\) running the Portnox™ Local RADIUS server. - [TACACS+ troubleshooting](topics/kb_tacacs_troubleshooting.md): In this topic, you will learn how to troubleshoot typical problems with the operation of the Portnox™ TACACS+ service. - [TACACS+: Firewall configuration](topics/kb_tacacs_local_firewall.md): In this topic, you will learn how to configure your firewall to make sure that the local TACACS+ instance can communicate with the cloud TACACS+ instances. - [TACACS+: connection security](topics/kb_tacacs_security.md): In this topic, you will find information about how Portnox Cloud secures the connection between a local TACACS+ server and Cloud services, including encryption and credential handling. - LDAP Broker - [General LDAP Broker troubleshooting](topics/kb_ldapbroker_troubleshooting.md): In this topic, you will learn how to troubleshoot typical problems with the operation of the Portnox™ Active Directory Broker. - [LDAP Broker installation errors](topics/kb_ldapbroker_troubleshooting_installation.md): In this topic, you will learn how to troubleshoot typical errors that happen during the installation of the Portnox™ Active Directory Broker. - [LDAP Broker Cloud connectivity](topics/kb_ldapbroker_troubleshooting_connectivity.md): In this topic, you will learn how to check if the Portnox™ LDAP Broker connects to the Portnox™ Cloud service. - [LDAP Broker logs and events](topics/kb_ldapbroker_logs.md): In this topic, you will learn where Portnox™ LDAP Broker logs are located in your file system and where you can find events related to the broker. - [LDAP Broker service location](topics/kb_ldapbroker_service.md): In this topic, you will find where to find the Portnox™ LDAP Broker service in the Windows Services console. - [LDAP Broker LDAP connectivity](topics/kb_ldapbroker_troubleshooting_ldap.md): In this topic, you will learn how to check if the Portnox™ LDAP Broker connects correctly to your on-premises LDAP server. - [LDAP Broker and NTLMv2](topics/kb_ldapbroker_ntlmv2.md): In this topic, you will learn how to troubleshoot LDAP Broker issues related to NTLMv2 configuration, permissions, enrollment, and authentication. - [LDAP Broker credential change](topics/kb_ldapbroker_credentials.md): In this topic, you will learn how to update the Portnox™ LDAP Broker configuration after you changed the access credentials to Portnox Cloud. - [LDAP Broker certificate](topics/kb_ldapbroker_certificate.md): In this topic, you will learn what the LDAP Broker certificate is used for and what to do if it expires. - AgentP - [AgentP general troubleshooting](topics/kb_agentp_troubleshooting.md): In this topic, you will learn how to troubleshoot typical problems during the installation and use of Portnox™ AgentP. - [Collecting AgentP logs](topics/kb_agentp_logs.md): In this topic, you will learn where to find Portnox™ AgentP logs in your file system and how to prepare them and send them to support. - [AgentP firewall open ports](topics/kb_agentp_firewall.md): In this topic, you will learn how to configure your firewall to make sure that the Portnox™ AgentP can communicate with Portnox™ Cloud. - [AgentP unattended enrollment mode](topics/kb_agentp_unattended.md): In this topic, you will learn how to switch an existing installation of Portnox AgentP for Windows to unattended enrollment mode by changing values in the Windows registry. - [How to configure AgentP to enroll with a specific domain](topics/kb_agentp_specific_domain.md): In this task, you will learn how to configure AgentP to enroll using a specific domain when multiple domains exist in your authentication repositories. - [AgentP repair \(Windows\)](topics/kb_agentp_repair.md): In this topic, you will learn how to repair a corrupted AgentP installation to restore full AgentP functionality or to enable AgentP to be uninstalled and reinstalled. - [AgentP manual deactivation](topics/kb_agentp_deactivate.md): In this topic, you will learn how to deactivate AgentP for Windows if the **Deactivate** button is disabled in the user interface due to a Portnox Cloud setting. - [AgentP manual removal](topics/kb_agentp_removal.md): In this topic, you will find methods of manually removing AgentP from your operating system if installation or uninstallation has failed. - Docker containers - [Docker logs collection](topics/kb_docker_logs.md): In this topic, you will learn how to access and collect Portnox Docker container log files either automatically using a script, or manually using the SSH protocol and the PuTTY application on Windows so that you can attach them to your support ticket. - [Docker debugging in ACI](topics/kb_docker_aci_debug.md): In this topic, you will learn how to debug your local RADIUS or local TACACS+ server in Azure Container Instances \(ACI\). - [Docker firewall configuration](topics/kb_docker_firewall.md): In this topic, you will learn how to configure your firewall to make sure that the Portnox Docker containers can communicate with Portnox Cloud. - NAS devices - [NAS troubleshooting](topics/kb_nas_troubleshooting.md): In this topic, you will learn how to troubleshoot known issues related to different NAS devices and their setup with Portnox Cloud RADIUS and local RADIUS. - [Cloud RADIUS FQDNs](topics/kb_radsec_fqdns.md): In this topic, you will learn about fully qualified domain names \(FQDNs\) for Portnox™ Cloud RADIUS servers. - [Cisco ARP probes](topics/kb_cisco_arp_probes.md): In this topic, you will learn why Windows devices encounter IP address conflicts during 802.1X reauthentication on Cisco switches due to ARP probe timing. - [Meraki hybrid auth failures](topics/kb_meraki_hybrid_auth.md): In this topic, you will learn why IoT devices fail to connect to Meraki switch ports when Hybrid authentication is used, and what configuration options are available to resolve this issue. - [DHCP Gleaning](topics/kb_dhcp_gleaning.md): In this topic, you will learn how to configure DHCP Gleaning on your Cisco Catalyst switch, if available. This will allow Portnox Cloud to perform IoT fingerprinting and anti-spoofing with no need for a dedicated DHCP forwarder. - Guest network \(captive portal\) - [Guest network troubleshooting](topics/kb_guest_troubleshooting.md): In this topic, you will learn how to troubleshoot typical problems with the guest network and the captive portal. - [Blocking the guest SSID](topics/kb_guest_blocking.md): In this topic, you will learn how to prevent domain Windows machines from automatically connecting to a guest Wi-Fi network, while still allowing users to access home or other personal Wi-Fi networks. - [WiNG – no authentication](topics/kb_guest_wing_noauth.md): In this topic, you will learn how to configure the Extreme WiNG captive portal without authentication but with user identification on the basis of the IP and MAC addresses. - Zero Trust Network Access - [ZTNA console application configuration options](topics/kb_ztna_console_options.md): In this topic, you will learn about the options available for ZTNA console applications: Remote Desktop \(RDP\), Secure Shell \(SSH\), Virtual Network Computing \(VNC\), and Telnet. - [ZTNA troubleshooting](topics/kb_ztna_troubleshooting.md): In this section, you will learn how to resolve common problems that you may encounter when you use Zero Trust Network Access. - [ZTNA certificate troubleshooting](topics/kb_ztna_troubleshooting_certificates.md): In this topic, you will learn how to troubleshoot the most common problems with certificates used for Portnox Zero Trust Network Access and accessed by web browsers. - [ZTNA certificate expiration](topics/kb_ztna_expiration.md): In this topic, you will find technical guidance on managing ZTNA certificate expiration and renewal for SSO-enabled web applications, including best practices for manual replacement and planning. - [Avast for macOS incompatibility](topics/kb_ztna_avast_macos.md): In this topic, you will learn why Portnox™ Zero Trust Network Access cannot work with the Avast antivirus on macOS. - Integrations - [Integration troubleshooting](topics/kb_integration_troubleshooting.md): In this topic, you will find frequently asked questions, answers, and troubleshooting tips related to Portnox™ Cloud integrations with third-party solutions. - [Intune app permissions](topics/kb_intune_app_permissions.md): In this topic, you will learn what minimum permissions are needed in Microsoft Intune and Azure for the Portnox™ Cloud app to work correctly. - [Portnox apps in Azure](topics/kb_azure_applications.md): In this topic, you will find information about the enterprise applications that Portnox Cloud installs in Azure and their purposes when integrating with Entra ID and Microsoft Intune. - [Okta integration](topics/kb_integrations_okta.md): In this topic, you will find details about how Portnox Cloud synchronizes with the Okta Workforce Identity Cloud. - [Impossible travel alerts](topics/kb_entra_impossible_travel.md): In this topic, you will learn what impossible travel alerts are in Entra ID, why they appear when using Portnox services, and how to prevent them for Portnox services in the future. - Risk assessment/Remediation - [Risk score calculation](topics/kb_risk_score.md): In this topic, you will find information about how Portnox Cloud calculates risk scores for risk assessment policies. - [Risk assessment application names](topics/kb_risk_applications.md): In this topic, you will learn how to find application names for risk assessment policies on Windows, macOS, Linux, Android, iOS, and via Portnox Cloud. - [Risk assessment service names](topics/kb_risk_services.md): In this topic, you will learn how to find service names on Windows and macOS to use them in risk assessment policies. - [Risk assessment OS version](topics/kb_risk_os_version.md): In this topic, you will learn how to find the operating system version for risk assessment policies on Windows, macOS, Linux, Android, and iOS devices. - [Risk assessment wildcards](topics/kb_risk_wildcards.md): In this topic, you will find information about which wildcard patterns are supported in risk assessment policy attributes and how to use them effectively. - [Risk assessment supported AVs](topics/kb_agentp_antivirus.md): In this topic, you will find information about the antivirus and firewall software supported by AgentP on Windows, macOS, and Linux, including examples of tested applications and guidance for unsupported programs. - [Custom uninstall scripts](topics/kb_risk_uninstalling.md): In this topic, you will learn why Portnox Cloud remediation policies using AgentP cannot uninstall some applications automatically, and how to work around this by creating a periodic script that detects the unwanted application and uninstalls it. - [Troubleshooting risk assessment](topics/kb_risk_troubleshooting.md): In this topic, you will find troubleshooting information for common issues related to Portnox Cloud risk assessment. - Fingerprinting and tracking - [Device make/model identification](topics/kb_device_identification.md): In this topic, you will find information about how Portnox Cloud identifies a device’s make and model. - [Map widget device location](topics/kb_map_location.md): In this topic, you will learn how the dashboard map widget determines a device’s location in Portnox Cloud. - Support - [Registration](topics/kb_support_registration.md): In this topic, you will learn how to register a Portnox Support Center account. ## Release notes - Release notes - [Release Notes – Portnox Cloud](topics/release_notes_cloud.md): In this topic, you will find release notes for Portnox Cloud. This includes the Portnox Cloud portal and the back-end for all primary products. It does not include updates to additional software installed separately on-premises or on user devices, as release notes for those components are provided separately. ## Support - Support - [Support portal](https://success.portnox.com/s/): Access our knowledge base, open and manage support tickets. - [Contact support](mailto:success@portnox.com): Open a ticket by emailing our support staff. - [Portnox Cloud status updates](https://status.portnox.com/): Monitor the status of the Portnox™ Cloud service and access information about past incidents. ## Glossary - [Glossary](glossary.md) - [802.1X](glossary.md#term_dot1x) - [AAA: Authentication, Authorization, and Accounting](glossary.md#term_aaa) - [Accounting](glossary.md#term_accounting) - [Agentless](glossary.md#term_agentless) - [Authentication](glossary.md#term_authentication) - [Authorization](glossary.md#term_authorization) - [CIDR \(Classless Inter-Domain Routing\)](glossary.md#term_cidr) - [DHCP \(Dynamic Host Configuration Protocol\)](glossary.md#term_dhcp) - [EAP \(Extensible Authentication Protocol\)](glossary.md#term_eap) - [Endpoint compliance](glossary.md#term_endpointcompliance) - [Fast reconnect](glossary.md#term_fastreconnect) - [IAM \(identity and access management\)](glossary.md#term_iam) - [IdP \(identity provider\)](glossary.md#term_idp) - [IoT \(Internet of Things\)](glossary.md#term_iot) - [IoT fingerprinting](glossary.md#term_iotfingerprinting) - [IPSK \(Identity Pre-Shared Key\)](glossary.md#term_ipsk) - [Network access layers](glossary.md#term_layers) - [LDAP \(Lightweight Directory Access Protocol\)](glossary.md#term_ldap) - [MAB \(MAC Authentication Bypass\)](glossary.md#term_mab) - [MAC address \(Media Access Control\)](glossary.md#term_mac) - [MAC spoofing](glossary.md#term_macspoofing) - [NAS \(network access server\)](glossary.md#term_nas) - [OIDC \(OpenID Connect\)](glossary.md#term_oidc) - [OUI \(organizationally unique identifier\)](glossary.md#term_oui) - [Policy enforcement](glossary.md#term_policyenforcement) - [RADIUS \(Remote Authentication Dial-In User Service\)](glossary.md#term_term_radius) - [RadSec \(RADIUS secure\)](glossary.md#term_radsec) - [SAML \(Security Assertion Markup Language\)](glossary.md#term_saml) - [SCEP \(Simple Certificate Enrollment Protocol\)](glossary.md#term_scep) - [SSO \(single sign-on\)](glossary.md#term_sso) - [TACACS+ \(Terminal Access Controller Access-Control System Plus\)](glossary.md#term_tacacs) - [Tenant \(software\)](glossary.md#term_tenant) - [X.500 Directory Specification](glossary.md#term_x500) - [ZTNA \(zero trust network access\)](glossary.md#term_ztna) ## Changelog - Changelog - [Changelog](topics/changelog.md): This list shows major changes to the documentation from January 2024 onward. It is updated when major new content is added or when changes to existing content may affect setup or provide additional information to the reader. Minor changes are not included.