I'm not sure about machine authentication, and for now would say it's not possible as the user needs to be in EntraID. Possibly you can assign a certificate with a user account for the machine certificate and authenticate through that path.
Documentation for Central NAC is here. In my previous response, I added a direct link to the BYOC (Bring your own certificate) section.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Jan 06, 2026 09:44 AM
From: Owais101
Subject: Aruba Central NAC with customer provided certificates
So it is possible through new central with premium NAC license?
Will it support machine authentication also?
Lastly, where can i read more about new Central NAC?
Original Message:
Sent: 1/6/2026 9:22:00 AM
From: Herman Robers
Subject: RE: Aruba Central NAC with customer provided certificates
Azure AD is now called Entra ID. And what you describe is called Bring Your Own Certificates in Central NAC.
Cloud Authentication and Poilcy (Classic Central) indeed supports Central provisioned certificates; Central NAC (New Central) supports in addition custom certificates as part of the Premium NAC License. Note that for Central NAC, configuration needs to be in New Central.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
Original Message:
Sent: Jan 06, 2026 09:06 AM
From: Owais101
Subject: Aruba Central NAC with customer provided certificates
Dear Experts,
One of the customer is planning for AOS 10 setup. They want to integrate with Azure AD and do authentication based on certificates that are issued internally by their firewall/server. Do we need Central NAC, and is it possible to use customer's own certificates for authentication of users and devices? so far what i have read, i think it may not be possible since cloud auth provisions its own certs?
------------------------------
Owais101
------------------------------