RADIUS (Remote Authentication Dial-In User Service)

Get reliable IT support and cyber security for your London business.

Contact us today to find out how we can help.

RADIUS is a client-server networking protocol that provides centralized authentication, authorization, and accounting (AAA) for users who connect to and use a network service.

Originally developed in the early 1990s for dial-up services, RADIUS is now widely used in enterprise environments to manage access to wired networks, Wi-Fi, VPNs, and remote access solutions. It allows network administrators to enforce consistent security policies across multiple access points and locations.

Why RADIUS Matters for London Businesses?

In London’s finance, legal, healthcare, education, and public sectors, controlling who can access network resources is critical for compliance, cybersecurity, and operational continuity. RADIUS helps organizations:

  • Enforce secure, centralized authentication across multiple sites and remote workers.
  • Maintain audit trails for regulatory compliance (GDPR, FCA, NHS Digital).
  • Integrate with Active Directory (AD) or other identity management systems for seamless user verification.

For organizations with multiple offices or shared workspaces, RADIUS ensures consistent security policies regardless of location.

Key Objectives of RADIUS

  1. Centralized Authentication – Verify user credentials through a central server.
  2. Granular Access Control – Apply role-based permissions to users and devices.
  3. Enhanced Security – Reduce reliance on shared credentials.
  4. Accounting & Auditing – Track user activity for compliance and troubleshooting.
  5. Scalability – Support thousands of users and multiple authentication sources.

How RADIUS Works (Simplified)?

  1. User Request – A device requests network access via a RADIUS-enabled access point, switch, or VPN server.
  2. Forward to RADIUS Server – The request is sent to a central RADIUS server.
  3. Authentication – The server verifies credentials against a user directory (e.g., Active Directory, LDAP).
  4. Authorization – Access is granted or denied based on policy rules.
  5. Accounting – The server logs session start, stop, and usage details.

Cyber Security Considerations

  • Encryption: RADIUS encrypts only passwords, not the full authentication packet — pairing it with a secure protocol like EAP-TLS is recommended.
  • Integration with MFA: Adding multi-factor authentication enhances security for remote and wireless access.
  • Logging & Monitoring: Comprehensive logging is essential for security investigations.
  • Policy Enforcement: Regularly review and update RADIUS policies to adapt to evolving threats.
  • Redundancy: Deploy backup RADIUS servers for high availability.

London Context – Local Considerations

  • Regulatory Compliance: FCA-regulated firms and NHS organizations often require auditable, centralized access controls.
  • Multi-Site Networks: Many London companies operate across multiple offices — RADIUS provides a unified authentication framework.
  • Hybrid Workforce: Supports secure authentication for both in-office and remote VPN access.
  • Shared Spaces & Co-Working: RADIUS ensures that only approved devices can connect to corporate VLANs in multi-tenant environments.

Example in Practice

A London-based law firm implements RADIUS authentication for staff Wi-Fi across its City of London and Canary Wharf offices. Employees connect using their domain credentials, which are validated against the firm’s Active Directory via the RADIUS server. The system logs all connection attempts for GDPR compliance and denies access to non-approved devices.