Skip to content
Avanet

Authenticate AP6 users with Microsoft Entra ID

Sophos Fusion Wireless can use Microsoft Entra ID as the identity provider for AP6 SSIDs with enterprise encryption. The workflow has three separate parts: a single-tenant app in Entra ID, an external IdP object in Sophos Fusion (formerly Sophos Central), and a matching EAP profile on the endpoints.

Quick procedure: Register an app in Entra ID without a redirect URI, record its client and tenant IDs, create a client secret, and set exactly Domain.Read.All as an Application permission and User.Read as a Delegated permission. Then go to My Products > Wireless > SSIDs > RADIUS > Add > Add external identity provider in Sophos Fusion, enter the four values, run Test connection, and assign the IdP to an AP6 enterprise SSID.

⚠️ Important boundary: This IdP supports only EAP-TTLS with PAP inner authentication here. RADIUS-assigned VLANs, RADIUS accounting, and captive portal backend authentication aren’t supported. If you need any of these features, this Entra workflow isn’t suitable.

Prerequisites and client decision

The intended user accounts must exist and be usable in Entra ID before you register the app. Microsoft documents creating, inviting, and deleting accounts in the linked user guide. Use an approved test account for the pilot, not a privileged administrator identity.

Account existence does not establish compatibility. Before deployment, build a tenant-specific pilot matrix covering the policies and identity types actually in scope: MFA and Conditional Access, passwordless accounts, guest accounts, and federated identities. TTLS/PAP cannot display an interactive browser challenge. Do not infer support from the Graph permissions. If a case cannot complete a real pilot sign-in or Sophos has not confirmed the authentication flow for it, stop that case and escalate it to Sophos Support and the tenant’s identity owner.

The client fleet determines the encryption mode:

  • Windows and Android: Sophos states that these devices don’t support TTLS/PAP with WPA3 Enterprise. The SSID must therefore use WPA2/WPA3 Enterprise.
  • Apple devices: They need an installed wireless configuration profile with EAP method: TTLS and Inner authentication: PAP. Sophos points to Apple Configurator for creating and installing it.
  • Other clients: The Sophos page makes no compatibility promise. Test EAP-TTLS/PAP and the selected enterprise mode with the actual models and operating system versions before rollout.

⚠️ Credential-protection stop condition: PAP sends a reusable password inside the TTLS tunnel. Every client must therefore validate both the expected server-certificate chain and server identity through approved MDM or client settings. Never disable certificate validation and never accept an unknown certificate. Sophos doesn’t publish the environment-specific server identity, trust chain, or all profile values. If the identity owner cannot provide approved values for them, deployment is blocked; do not guess them.

Register the Entra app and secure its values

  1. Sign in to the Microsoft Entra admin center.
  2. Open Entra ID > App registrations and select New registration.
  3. Enter a unique name, such as Sophos-Central-AP6-Auth.
  4. Under Supported account types, select Single tenant only.
  5. Leave Redirect URI blank unless your environment requires one, then select Register.
  6. On the app’s Overview, record the Application (client) ID and Directory (tenant) ID.
  7. Open Certificates & secrets > Client secrets > New client secret, enter a description, select a lifetime that fits your rotation process, and select Add.
  8. Use Copy to clipboard immediately to store the secret value in the approved secret store. It isn’t displayed again; if you lose it, you must create another one.
  9. Go to Entra ID > Domain names > Custom domain names, record the intended domain’s Name, and verify that its Status is Verified.

You now have four environment-specific values for Sophos Fusion: Client ID, Client secret, verified Domain name, and Tenant ID. The IDs belong in the intended configuration, but the secret must not be placed in tickets, screenshots, chat, or version control.

Set only the documented Graph permissions

In the registered app, open API permissions > Add a permission > Microsoft Graph. Add the permissions separately so that the permission type is explicit:

  1. Select Application permissions, search for Domain.Read.All, select it, and select Add permissions.
  2. Open Add a permission > Microsoft Graph again, select Delegated permissions, search for User.Read, select it, and select Add permissions.
PermissionTypeAdmin consent required
Domain.Read.AllApplicationYes
User.ReadDelegatedYes

Select Grant admin consent for and Yes. In the final list, verify—not merely assume—that Domain.Read.All shows Application, User.Read shows Delegated, and both show Granted. Sophos specifies this exact combination; don’t add extra Graph permissions just in case. Who can configure and consent depends on your Entra administration, so this guide doesn’t invent a directory role.

Add Entra ID as the IdP in Sophos Fusion

  1. Sign in to Sophos Fusion at https://fusion.sophos.com, then open My Products > Wireless > SSIDs > RADIUS.
  2. Select Add > Add external identity provider.
  3. Under Name, enter a unique display name, such as HQ-Entra-ID. This name appears on the RADIUS page and in an AP6 SSID’s server list.
  4. Enter the Application (client) ID as Client ID.
  5. Enter the secret value you secured earlier under Client secret.
  6. Enter the verified custom domain name under Domain name.
  7. Enter the Directory (tenant) ID as Tenant ID.
  8. Select Test connection. Select Save only after a success message.

Treat acceptance as three separate checks. Test connection checks the Fusion-to-IdP configuration only. A real client connection checks the TTLS/PAP authentication exchange and the tenant policy for that pilot identity. Only post-authentication user traffic checks addressing, DHCP, DNS, VLANs, the gateway, and firewall rules. Success at one layer does not prove either later layer; this guide makes no undocumented claim about the cloud credential path.

Assign the IdP to an AP6 pilot SSID

First inventory every Enterprise SSID already assigned to the candidate pilot AP, including its frequency bands and selected RADIUS server or IdP. AP6 supports only one RADIUS configuration per frequency band. If another Enterprise SSID uses a different server or IdP on an overlapping band, saving the new assignment can overwrite the band’s existing RADIUS configuration, after which the new primary selection can affect both SSIDs. Prefer an AP with no conflicting Enterprise SSID.

Create or edit the Enterprise SSID using the AP6 RADIUS and WPA3 Enterprise workflow, select HQ-Entra-ID, and initially assign it to one nonconflicting pilot AP. For Windows or Android, select WPA2/WPA3 Enterprise. Keep RADIUS VLAN assignment, RADIUS accounting, and captive portal backend authentication disabled. Before Save, record every affected SSID’s previous IdP/RADIUS selection, bands, and AP assignments. Stop before Save if any band overlaps with a different selection or the baseline is ambiguous; choose another pilot AP or escalate to Sophos Support.

Validate before rollout

  1. Fusion-to-IdP: Test connection must succeed.
  2. Real client authentication: Connect with an approved Entra pilot identity and the approved TTLS/PAP profile; certificate-chain and server-identity validation must succeed without accepting prompts or unknown certificates.
  3. Tenant policy matrix: Run separate real sign-ins for every in-scope combination of MFA/Conditional Access, passwordless, guest, and federated policy. Record supported and rejected cases. Stop and escalate any unsupported or ambiguous case; one ordinary account proves no general Entra compatibility.
  4. Negative test: Verify that a purpose-built disabled or otherwise unusable test account gets no Wi-Fi access. Don’t lock production accounts through repeated failures.
  5. User traffic: Verify the intended IP configuration, DNS, VLAN path, gateway, and access to exactly the approved destinations. Association or authentication alone is insufficient.
  6. Client and regression matrix: Test each intended OS, device type, and policy case separately, then retest every existing Enterprise SSID on the pilot AP. Add APs only in small batches after documenting success.

Troubleshoot by symptom

Test connection fails: Compare Client ID and Tenant ID with Overview, the domain with its Verified status, and the secret with the value copied at creation. Then verify that both Graph permissions have the correct type and show Granted. Replace an expired or lost secret with a new one and update the Fusion IdP too.

Test connection succeeds, but Wi-Fi sign-in fails: This makes the Fusion integration a less likely cause but doesn’t prove the client works. Check that the EAP profile uses TTLS/PAP, the user is usable, and the SSID has the right encryption. Windows and Android require WPA2/WPA3 Enterprise.

An Apple device unexpectedly asks for settings or certificate trust: Confirm that the intended wireless configuration profile is installed and targets the correct SSID. Don’t work around the problem by accepting unknown certificates without control; resolve missing profile values through the responsible Apple or MDM process.

Authentication succeeds, but DHCP, DNS, or destinations fail: The fault is after authentication in the data path. Check the client address, VLAN and switch path, DHCP, gateway, DNS, and firewall rules. Don’t grant additional Graph permissions to fix a network fault.

Roll back safely and review permissions

If the pilot fails, assign it to no further APs. Remove the new assignment, then compare every affected Enterprise SSID with the recorded baseline. Removal alone may not restore the per-band configuration automatically. Explicitly restore the previous IdP/RADIUS selection, original frequency bands, and AP assignments, then save and retest known existing authentication and user traffic. If the prior state or restoration path is ambiguous, stop and escalate to Sophos Support instead of making further production changes.

Delete the IdP object from the Fusion RADIUS page only after its SSID count or assignments show that no SSID still uses it. Revoke or remove the client secret or Entra app only after that and in coordination with the app owner; otherwise, remaining assignments are left without working authentication. After removal, verify that the object is no longer selectable and that existing access still works.

In operation, periodically review the secret expiry, app owner, both Graph permissions, and assigned SSIDs. Remove any unneeded extra permissions; this integration should retain only the combination documented by Sophos.