The RADIUS (Cloud Auth in this case) will override the Role assignments that are configured in the WLAN configuration. TBH, I would not use that feature in most cases. Please use Cloud Auth to return the correct role.
Regarding VLAN, configure the VLAN ID within the User Role. The User Role is configured within the AP group.
Original Message:
Sent: Jul 30, 2025 11:38 AM
From: ntlong3
Subject: Central – AP-Login to WiFi Cloud Auth directly by Username/Password
I switched to Security Level Visistor, Cloud Guest type.
I can redirect to Captive Portal after Login to SSID and authenticate on Google Account.
After successful authentication, I get the correct role that I am specifying in Identity Store of Google Workspace on Aruba Central, get the correct Access Rules, but do not get Vlan Assignment of each role and when checking in Client tab, Client Name is displayed as a series of numbers, not Email User.
One more thing, that is the problem of Add Role Assignment in WLANs configuration, I tried some properties such as Group; Group-Name but it cannot be Assigned, it only gets the default Role assigned in Identity Store of Google Workspace configured in Security > Autthentication & Policy > User Access Policy.
Original Message:
Sent: Jul 29, 2025 03:56 AM
From: willembargeman
Subject: Central – AP-Login to WiFi Cloud Auth directly by Username/Password
That is not possible with a cloud IdP. With username/password auth on WPA2/3 networks NTLM is being used. NTLM is deprecated and not available with cloud IdP's.
So the only option with Enterprise networks now is to used the Onboard app. Other option is to use the MPSK option in Cloud Auth. You will then generate a (M)PSK that is unique for an user (tied to for example Google Workspaces). But this only works with WPA2-PSK networks.
------------------------------
Willem Bargeman
Systems Engineer Aruba
ACEX #125
Original Message:
Sent: Jul 29, 2025 03:29 AM
From: ntlong3
Subject: Central – AP-Login to WiFi Cloud Auth directly by Username/Password
I want WPA3-Enterprise, when I enter user/pass it can't connect but when I use Onboard and Install Network Profile it connects successfully. I just want to simply use user/pass
Original Message:
Sent: Jul 29, 2025 03:17 AM
From: willembargeman
Subject: Central – AP-Login to WiFi Cloud Auth directly by Username/Password
Do you mean with a captive portal? 802.1x auth based on username password is not possible with Cloud IdP's.
------------------------------
Willem Bargeman
Systems Engineer Aruba
ACEX #125
Original Message:
Sent: Jul 29, 2025 02:05 AM
From: ntlong3
Subject: Central – AP-Login to WiFi Cloud Auth directly by Username/Password
I have a Google Workspace. I want to configure SSID on Aruba Central so that users just need to connect to WiFi and enter user/pass information without using Onboard APP.
Please help me.
-------------------------------------------