Information & Communications Technology

Network Access Control and Device Posture Enforcement

Design and roll out network access control that authenticates every device with 802.1X, checks its security posture before granting access, and moves unmanaged or non-compliant endpoints to a controlled quarantine network.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

Networks that trust any device plugged into a switch port or associated to a wireless network are exposed to rogue devices, unpatched laptops and IoT equipment that was never meant to reach sensitive systems. Network access control closes that gap by authenticating a device or user before granting access and then checking whether the device meets a defined security posture, rather than assuming a connection request is safe by default. This course covers 802.1X authentication with RADIUS, including certificate-based EAP-TLS and username-based PEAP, and MAC authentication bypass for devices that cannot run a supplicant. Participants design device profiling to identify what is connecting, posture assessment that checks patch level, antivirus status and disk encryption, and dynamic policy that places compliant devices on their intended VLAN while redirecting others to a quarantine network for remediation. The course also covers guest and bring-your-own-device onboarding workflows and a phased rollout from monitor mode through low-impact enforcement to a fully closed access policy, so control is added without locking out legitimate users on day one.

Expected Learning Outcomes

01

Design 802.1X authentication using EAP-TLS and PEAP appropriate to different device types.

02

Configure MAC authentication bypass and device profiling for devices without a supplicant.

03

Build posture assessment policy that checks patch level, antivirus status and encryption state.

04

Apply dynamic VLAN assignment and downloadable ACLs based on authentication and posture results.

05

Design a quarantine network and remediation workflow for non-compliant or unknown devices.

06

Build guest and bring-your-own-device onboarding flows that do not require IT intervention.

07

Plan a phased NAC rollout from monitor mode to closed enforcement without locking out users.

Who Should Attend

01

Network security engineers implementing or expanding network access control.

02

Network engineers configuring 802.1X on switches and wireless controllers.

03

Security architects designing zero trust access for wired and wireless networks.

04

IT teams managing bring-your-own-device and guest access programmes.

05

Compliance and risk teams requiring evidence of endpoint posture control.

06

Systems integrators deploying NAC solutions for enterprise clients.

Course Modules

Select any module to see its sessions and points.

01

802.1X Authentication Foundations

2 sessions · 8 points

Session 1EAP Methods, RADIUS and Supplicants

  • Compare EAP-TLS and PEAP and decide which suits managed, unmanaged and IoT devices.
  • Configure a RADIUS server as the policy decision point for authentication requests.
  • Deploy client certificates and configure supplicants for certificate-based authentication.
  • Design a fallback authentication method for devices that cannot complete 802.1X.

Session 2MAC Authentication Bypass and Device Profiling

  • Configure MAC authentication bypass for printers, phones and other supplicant-free devices.
  • Profile connecting devices using DHCP fingerprinting and other passive identification methods.
  • Build a device inventory that links a profiled device type to an access policy.
  • Handle unknown or unprofiled devices with a safe default access policy.
02

Posture Assessment and Compliance Policy

2 sessions · 8 points

Session 1Endpoint Posture Checks

  • Define posture checks covering patch level, antivirus status and disk encryption.
  • Choose between agent-based and agentless posture assessment for different device classes.
  • Integrate posture assessment with existing endpoint management and detection platforms.
  • Set posture re-check intervals so compliance is monitored continuously, not just at login.

Session 2Policy Design and Access Decisions

  • Write access policies that combine identity, device type and posture into one decision.
  • Assign dynamic VLANs and downloadable ACLs based on the outcome of policy evaluation.
  • Use change of authorization to update a session's access without forcing reconnection.
  • Test policy logic against representative compliant and non-compliant device scenarios.
03

Quarantine, Remediation and Onboarding

2 sessions · 8 points

Session 1Quarantine Networks and Remediation

  • Design a quarantine VLAN that gives a non-compliant device only remediation resources.
  • Build a remediation workflow that guides a user through fixing a posture failure.
  • Set time limits and escalation paths for devices that remain non-compliant.
  • Log quarantine events to support both user support and security investigation.

Session 2Guest and BYOD Onboarding

  • Design a self-service guest portal that issues time-limited, sponsor-approved access.
  • Build a bring-your-own-device onboarding flow that installs a certificate without IT staff.
  • Separate guest and BYOD traffic from corporate resources at the network policy level.
  • Set expiry and renewal rules for guest and personal device access credentials.
04

Deployment, Rollout and Operations

2 sessions · 8 points

Session 1Phased Enforcement Rollout

  • Run a monitor-mode phase that reports what would be blocked without affecting access.
  • Move to low-impact mode that applies limited access rather than an outright block.
  • Escalate to closed mode once exception cases have been identified and resolved.
  • Communicate each rollout phase to affected users and support teams in advance.

Session 2Ongoing Operations and Zero Trust Alignment

  • Monitor authentication and posture failure trends to catch systemic issues early.
  • Handle switch and controller configuration changes needed as device types evolve.
  • Align network access control policy with a broader zero trust access strategy.
  • Report access control coverage and exceptions to support audit and compliance needs.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course