Do RADIUS Servers use AD?

You know what facilitated back-office IT functions for any business twenty years ago? It was Active Directory (AD), Microsoft’s user directory system. Active Directory simplified the task for organizations to manage their resources from a single console, so offices everywhere used AD. A RADIUS server is an authentication server that can use the information contained […]

Do RADIUS Servers Use Active Directory? Here’s the Answer
Key Points
  • RADIUS servers can authenticate users without using Active Directory, although they still require a reference directory, such as Azure AD or Okta.
  • Many organizations are moving to cloud-based identification solutions for greater flexibility and to avoid being bound into on-premises infrastructure, such as Active Directory.
  • By combining certificate-based authentication with RADIUS, organizations can improve security while eliminating vulnerabilities associated with traditional password systems.

You know what facilitated back-office IT functions for any business twenty years ago? It was Active Directory (AD), Microsoft’s user directory system. Active Directory simplified the task for organizations to manage their resources from a single console, so offices everywhere used AD.

A RADIUS server is an authentication server that can use the information contained in your directory to authenticate and authorize users, but does that mean it needs to use AD today? Let’s find out.

Why Would Organizations Want to Use Active Directory?

Technically, Active Directory (AD) is a database of critical information about users, devices and their environment, coupled with other Microsoft services to help users securely connect with the resources they need.

The Microsoft services are what allow people to access resources while the AD contains details such as the user’s job profile, phone number, permissions and passwords.

AD is a game changer in that it centralizes identity, rather than storing them on a per-computer basis.

It enables organizations to manage devices from a single location, creating group policies and segmenting the network to maintain secure perimeters.

Where Does RADIUS Come In?

So, what does a Remote Authentication Dial-In User Service (RADIUS) server have to do with AD?

In short, RADIUS servers authenticate users and devices attempting to access your network resources. Your Identity Provider (IdP) can provide critical identity information for authentication and authorization during this process.

Here is a quick explanation under 5 minutes on how RADIUS (also known as AAA server) secures your network.

Authentication Process

The following is what the RADIUS authentication process looks like:

  1. The user attempts to connect to the network for the first time with a unique credential. The access request is sent to the access point, which is then sent to the RADIUS server.
  2. The credential is verified against the information stored in the directory or the RADIUS server itself.
  3. If the match is made, then the server accepts the user by sending an Access-Accept message (along with parameters or restrictions regarding what you can utilize on that network) back to the access point.
  4. The user is rejected through an Access-Reject message if the match is not made.

Prefer a visual explanation instead? Check out the video below.

Why Is RADIUS Needed?

To have all your users connect to your networks, you need RADIUS to maintain a central authentication system. The image below shows where a RADIUS server fits and the authentication process.

Illustration of RADIUS authentication overview.

User identities are stored in directories such as Okta, Azure, G-Suite and AD. RADIUS connects all your users to the company network with their own unique credentials eliminating the use of pre-shared keys.

In other words, RADIUS can make it possible for you to leverage the network access control policies you’ve already created in your identity management system and apply them to your Wi-Fi or VPN.

Do RADIUS Servers Need Active Directory?

RADIUS doesn’t specifically need Active Directory, but it does need a directory to reference for authentication and authorization purposes.

RADIUS can use AD for that directory, but AD tends to tie organizations to on-premises infrastructure and isn’t the best solution for those looking to move to the cloud.

See your security gap before attackers do.

See continuous trust in action on a platform that includes RADIUS, PKI and AI security.

Customize Your Video Demo

Can We Use AD Without On-Premises Hardware?

AD is on premises only. It requires a physical server in a physically secured location, which necessarily involves a lot of human resources to set up and manage.

The next question is: can you have AD in the cloud?

Unfortunately, no. Active Directory is a service that’s still reliant on the legacy authentication protocol, Lightweight Directory Access Protocol (LDAP). This ties it to on-premises architecture.

If you’re looking for a way to migrate your identity management infrastructure to the cloud, Microsoft offers an alternative Identity Provider called Azure AD (Microsoft Entra ID).

Of course, there are other options, as well, such as Google or Okta.

What Locks You to the IdP?

Imagine if your IdP leaves no choice but to choose systems and applications that the IdP has the capability to control. This is what a Microsoft AD does. It was mainly designed to control was Windows-based devices.

As organizations depended more on Microsoft AD, they were left with no choice but to choose devices and applications that could be controlled by AD.

Many organizations want to migrate to the cloud to start implementing certificate-based solutions, but the transition can be difficult if you have a Microsoft AD environment.

A well-designed IdP should give organizations control over all major systems (Unix, Linux, Mac, Windows), cloud and on-premises servers (e.g. AWS, GCP, internal data centers), networks (Cloud RADIUS), data through physical and virtual file servers, single sign-on to applications (web and on-premises), and more through one central web platform.

Note: Thus, it’s important to choose an IdP that can fully move to the cloud without locking you into a particular ecosystem.

Reasons Why You Don’t Want to Be Locked Into On-Premises

There are two major reasons why relying solely on on-premises AD can become a limitation:

  1. The growing diversity of IT environments
  2. The shift toward cloud-based infrastructure

Heterogenous IT Environment

20 years ago, when AD was just introduced, the IT environment was generally on-premises and Windows-based. Microsoft specifically designed AD for the Windows platform and the applications were largely Windows-based as well.

Today, the IT environment is much more diverse, and while Microsoft continues to be a dominant presence, it is now far from the only one.

Organizations can now choose from a range of operating systems, including Macs, Linux devices, and even Chromebooks. Any Identity Provider an organization uses needs to be compatible with the devices on the network.

Cloud First

Ever since the pandemic hit, organizations are rethinking everything, and cloud services have been witnessing a steep rise. There are cloud-native computing options for everything, from servers and databases to networking and software.

Companies are transitioning to the cloud as it provides flexible resources, cost-effective options and practical, accessible tools.

Rather than maintaining on-premises data centers and servers, the software as a service (SaaS) model of cloud computing lends itself to a “pay-as-you-use” plan that can scale to fit your needs.

Note: In this increasingly cloud-based world, using traditionally on-premises infrastructure can hold you back.

Some organizations have attempted to supplement their AD with Azure as a bridge to the cloud, but because Azure doesn’t support LDAP directly, this requires syncing with an on-premises AD server.

What Are the Alternatives to AD?

A cloud replacement is the best for modern challenges. Moving your identity management to the cloud means you don’t have to worry about upgrading hardware every few years, conducting your own software maintenance and patching, and managing availability and security.

Additionally, cloud solutions embrace the disparate IT setup modern organizations use.

Today, organizations don’t necessarily need AD for a directory because of the rise in SaaS companies offering directory instances in their software. Examples of cloud alternatives to AD include Google, Okta and Azure AD.

The security plan that scales with you.

Our solutions can scale from mid-market to global enterprises. Compare options and see how our solutions protect you from costly breaches and ensure peace of mind.

Check Our Prices

How to Move Beyond Your On-Premises Environment

There are two main reasons organizations choose on-premises infrastructure:

  1. They want to build their infrastructure themselves with complete control over its construction
  2. They simply already have the on-premises infrastructure and don’t see a need to move everything to the cloud just yet

Moving to the cloud will require some consideration of your infrastructure architecture.

If the organization is cloud-based or shifting to the cloud, then a cloud directory is the best choice. If, however, the organization is maintaining an on-premises Microsoft model, Active Directory is a logical choice.

But, even if you choose to go the on-premises Windows-centric route, it is a good idea to examine what cloud-based infrastructure can do for you.

IT admins who work with your on-premises hosted servers, storage and data processing hardware, software, applications and infrastructure will know this. It takes time, expertise and money to maintain and update these resources to keep pace with market demands and growth.

When you shift to cloud, you can cut IT and operating costs and gain the resilience to scale technology as and when your business demands change.

Cloud computing has been lauded as a revolution in IT. When you consider the benefits it can bring, it’s not surprising that so many organizations have been eager to upgrade to the cloud

For an IT environment that uses Microsoft products and services and wants to transition to the cloud, Azure AD can help with the transition.

Warning: Both Azure and AD networks authenticate users with PEAP-MSCHAPv2, which contains a significant vulnerability in its encryption that can allow a hacker to gain access to user login information in plain text.

To increase your network security, you can enable users to authenticate uniquely to the network by setting up a certificate-backed authentication.

Azure customers who set up certificates with SecureW2 use simple onboarding software for BYODs and gateway APIs for their managed devices. SecureW2 offers an easy-to-use Public Key Infrastructure (PKI) that easily integrates with Azure for use as an IdP.

Watch the video below to understand how the SecureW2 Cloud RADIUS platform integrates with Azure AD.

Modern Passwordless Authentication Designed for Cloud Identities

Cloud based identity providers offer the flexibility organizations need. They’re scalable, don’t rely on legacy protocols like LDAP and don’t require expensive on-premises infrastructure or security.

AD’s on-premises infrastructure has become a hindrance for many organizations trying to migrate to the cloud. On-premises technology just doesn’t offer the same versatility or security as cloud services, which is why many admins are looking to cloud IDPs.

By integrating cloud IdP with the JoinNow Dynamic PKI and JoinNow Cloud RADIUS, organizations can leverage the network access policies they’ve already established in their IDP and apply it to their Wi-Fi and VPN — regardless of location.

However, if your organization needs to use AD, the SecureW2 Cloud RADIUS platform can still provide premier passwordless authentication in tandem with digital certificates leveraging your Active Directory.

Check out our pricing page to see if our solutions can help secure your network.