Network access control (NAC) is a security approach that checks devices, and often their users, when they try to connect to a wired or wireless network, then decides whether to allow them on and what they can reach. A company laptop that meets policy might get full access, a guest phone only internet access, a printer only the print server, and an unknown device nothing at all or a quarantine network. NAC also gives IT a running inventory of what is connected.
At a glance
- NAC applies policy at the moment a device connects to the local network, by cable or Wi-Fi.
- Devices are identified by user sign-in, certificates or, for devices that can’t sign in, profiling of their characteristics.
- Many NAC systems can check device health, such as whether security software is running, before granting access.
- Access is usually enforced by placing the device on a specific network segment or applying access rules on the switch or wireless network.
- Visibility is a major benefit: an up-to-date list of devices connecting through the switches and access points NAC controls.
What problem it solves
On many office networks, anyone who plugs a device into a wall port or gets the Wi-Fi password can reach a large part of the network. That includes visitors, contractors, employees’ personal devices and connected equipment such as cameras, printers and building systems that IT may not even know about. A compromised or unmanaged device on the inside network can scan for targets and spread malware.
NAC replaces this open door with a checkpoint. It aims to keep unknown and unauthorized devices off the corporate network, places devices on the segment that matches their role, and keeps unknown or non-compliant devices away from sensitive systems. As bring your own device (BYOD) programs and connected devices multiply, it also helps IT see what is actually connected, which supports IoT security, audit responses and incident investigations.
How it works
Authentication. When a device connects, the switch or wireless access point asks it to identify itself, often using the 802.1X standard with user credentials or a device certificate checked against a central policy server. Devices that can’t do this, such as printers and cameras, are identified by their hardware address and profiled by characteristics like manufacturer and traffic patterns.
Posture checks. Some NAC deployments check whether a device meets requirements, such as an up-to-date operating system or running endpoint protection, often using an agent or information from endpoint management tools.
Authorization. Policy decides what access the device gets, typically by assigning it to a virtual local area network (VLAN) or applying access rules. Corporate devices, guests, contractors, IoT devices and non-compliant machines can each land on different segments, building on your network segmentation design.
Guest and onboarding. Guest portals and self-service onboarding let visitors and approved personal devices connect with limited access.
Monitoring and response. NAC keeps a log of who and what connected, when and where. Many products integrate with firewalls and security tools so a device flagged as compromised can be quarantined automatically.
When it matters for buyers
- When refreshing switches and Wi-Fi. NAC depends on wired and wireless LAN infrastructure that supports it, so plan them together.
- When auditors or customers ask about device control. Many security frameworks expect controls over which devices can connect.
- When you have many unmanaged or IoT devices. NAC provides the visibility and segmentation they need.
- When offices are open to visitors, contractors or shared space. Physical network ports become a real exposure.
- When adopting a zero trust approach. NAC applies identity- and device-based access to the local network.
Our wired and wireless LAN infrastructure overview covers the switching and Wi-Fi that NAC runs on.
Questions to ask vendors
- Does your NAC work with our existing switches and wireless equipment, or does it require specific hardware?
- How do you identify and handle devices that can’t authenticate, such as printers, cameras and medical or building equipment?
- Is a device agent required for posture checks, and on which operating systems?
- Can we deploy in monitor-only mode first, and how do we avoid locking users out?
- How does it integrate with our identity provider, endpoint management and firewalls?
- Is it delivered as an appliance, virtual machine or cloud service, and how is it licensed?
- What happens to network access if the NAC server is unavailable?
How it differs from ZTNA
Zero trust network access (ZTNA) grants users access to specific applications, typically over the internet, checking identity and device for each connection, generally without placing the user on the network as a whole. It mainly replaces remote access VPNs. NAC controls access to the local wired and wireless network itself, deciding which devices can connect and which segment they join. The two address different points of entry and work well together: NAC for devices in the office, ZTNA for users reaching applications from anywhere.
