arrow_back Back to Insights NETWORK SECURITY

Rolling Out Network Access Control Without Locking Everyone Out

October 2026 10 min read

Network access control has a reputation for causing outages, and the reputation is earned. The product is installed, enforcement is switched on, and by mid-morning the printers are offline and somebody senior cannot get on the network.

The technology is rarely at fault in that story. Enforcement was switched on before anyone knew what was plugged in. This guide sets out the order I do it in instead. The principles are vendor-neutral. The product I work with is FortiNAC, on an estate that spans a Premier League football club’s stadium and training ground, where disruption on a match day is not an option.

What NAC is for

Network access control does two jobs, in this order:

Most of the value in the first months comes from the first job. Many organisations have never had a complete, current list of what is on their network, and control is only as good as that list.

Why rollouts go wrong

Every network that has been running for a few years contains things nobody documented: a switch under a desk, a door controller, a display screen, a device installed by a contractor. A policy written from the documentation covers the devices people remember. Enforcement applies it to the devices that are actually there, and each undocumented one becomes a support call.

The fix is to separate the two jobs in time. Run visibility on its own until the list stops surprising you, and bring in control in small steps after that.

Prerequisites: what has to be true before you start

NAC sits on top of the switching and authentication you already have. If those are inconsistent, it will be too. I check four things first, usually as part of a wider network security audit.

An accurate switch inventory

Every switch and wireless controller, with model, firmware version, management address, location and what its uplinks connect to. NAC products talk to switches directly, and feature support depends on model and firmware. Check each one against the NAC vendor’s current compatibility documentation.

A consistent VLAN design

NAC places devices into segments, so the segments have to exist and mean the same thing everywhere. A workable plan for most organisations separates:

The same VLAN should carry the same purpose at every site, and the rules between segments should be written down and enforced on the firewall. Without that, moving a device from one VLAN to another achieves very little.

Managed switches, configured the same way

The NAC system needs to read from and write to the switches. That means management access configured consistently: SNMPv3 in place of the older unencrypted versions, syslog sent to a known collector, time synchronised and individual administrative logins. Small configuration differences are a common reason a rollout works in one building and misbehaves in the next.

RADIUS, and a decision about authentication

Two methods do most of the work, and they are not equivalent.

802.1X is real authentication. The device proves its identity, ideally with a certificate issued by your own certificate authority and delivered by a management tool such as Intune. It is the right method for managed laptops, desktops and phones. It needs a working RADIUS service and a certificate process, and the device has to support it.

MAC authentication bypass (MAB) is for devices that cannot do 802.1X. The switch presents the device’s MAC address and the RADIUS or NAC system decides what to do with it. It works with almost anything. Its weakness is that a MAC address can be copied, so treat MAB as a way to recognise a device and put it in a restricted segment. It should never be a route to the corporate network.

Phase 1: visibility and profiling, with no enforcement

The NAC system is connected to the switches and wireless, and does nothing except watch. It builds a list of every device it sees and where it is connected, and it profiles each one: what kind of device it appears to be, based on signals such as the manufacturer prefix of the MAC address, how it requests an address and how it behaves on the network.

Nothing changes for users in this phase. How long to run it depends on the organisation. It needs to cover a full cycle of normal activity, including whatever happens only occasionally: month-end, an event, a maintenance visit. Devices that connect once a month are the ones locked out later if this phase is cut short.

Phase 2: classify and clean up

This is where the project succeeds or fails.

The aim is that when enforcement arrives, every device is already in the segment the policy would put it in.

Mapping devices to methods and segments

By the end of phase 2 you should be able to fill in a table like this for your own estate.

Device typeAuthenticationVLAN / segmentEnforcement approach
Managed laptops and desktops802.1X with device certificatesCorporateEnforce early; failures go to a restricted remediation segment
Managed phones and tablets802.1X on corporate Wi-FiCorporate or mobileEnforce with the wireless rollout
PrintersMAB plus profilingPrintersRegistered in advance; firewall limits them to print traffic
CCTV and door controlMAB plus profilingCCTV / physical securityRegistered in advance; no route to user networks
Operational technology and AVMAB, sometimes fixed port assignmentOT / building systemsEnforce last, with the system owner present
Guest devicesGuest portal or sponsored accessGuestInternet only, isolated from internal segments
Contractor laptopsSponsored, time-limited registrationContractor or guestAccess limited to the systems they are there to work on
Unknown devicesNoneIsolationNo access until identified; alert raised

Phase 3: enforce one segment or one site at a time

Enforcement starts with the smallest, best-understood part of the network: the IT team’s own floor, or one building. I work through the same steps each time:

  1. Choose the scope. A named set of switches or ports, agreed with the people who work there.
  2. Test the rollback first. Before enforcing, prove that you can return those ports to their previous configuration quickly, and that someone on site knows how.
  3. Know the failure behaviour. Decide what happens to a port if the RADIUS or NAC service cannot be reached, and test it. Whether ports fail open or closed is a decision made per segment.
  4. Enforce in working hours, with support on hand. Problems should appear while someone is there to fix them.
  5. Leave it for a period. Record every exception before moving on.
  6. Move to the next scope. Each one goes faster, because the exceptions repeat.

Handling exceptions

Exceptions are normal. Each one should be deliberate, recorded and as narrow as possible.

Freezes for event days and busy periods

Some organisations have times when network disruption is unacceptable. For a venue it is an event day, and for a retailer it is peak trading. Build change freezes into the plan from the start: no new enforcement, no policy changes and no switch firmware updates inside the window.

The freeze also shapes the visibility phase. Devices that appear only during an event, such as temporary equipment or a broadcast partner’s kit on its own VLAN, need to be seen and classified before any policy touches the ports they use.

Firewall, endpoint and SIEM integration

NAC decisions improve when they use more than the network’s own view. A firewall can report that a device is behaving badly, and an endpoint management or security agent can report whether a laptop is compliant. The NAC system can respond by moving the device to a restricted segment. What is available depends on your products and licences, so check the vendor documentation. Introduce automated responses as cautiously as enforcement, because a quarantine triggered by a false positive is an outage too.

Send the logs somewhere they will be read. NAC events, RADIUS authentication results and firewall logs belong in a SIEM such as Microsoft Sentinel, alongside identity and endpoint logs, so an investigation follows one timeline. This is part of the wider infrastructure and security picture, and the case studies describe an estate where it was built that way.

Ongoing operation

A NAC deployment that nobody tends will degrade into a list of exceptions. Agree these before the project closes:

Done in this order, the day enforcement is switched on should pass without anyone outside IT noticing.

FAQ

802.1X is real authentication: the device proves its identity to the network, ideally with a certificate, before the switch port or wireless network lets it on. It suits managed laptops, desktops and phones. MAC authentication bypass is the fallback for devices that cannot do 802.1X, such as many printers, cameras and building systems. The switch presents the device’s MAC address and the RADIUS or NAC system decides where to place it. A MAC address can be copied, so MAB should only ever lead to a restricted segment, never to the corporate network.
It should not, if it is done in phases. During visibility and profiling nothing changes for users at all. Disruption comes from enforcing a policy on devices nobody knew about, so the work goes into classifying every device and moving it to the right segment before enforcement. Enforcement then starts with a small, well-understood area, in working hours, with a tested rollback and support on hand.
It depends on what your current switches can do. They need to be managed switches that support 802.1X and MAC authentication against a RADIUS server, can place a port in a VLAN dynamically, offer secure management such as SNMPv3, and are supported by the NAC product at the firmware version you run. Check each model against the NAC vendor’s compatibility documentation. Unmanaged switches cannot take part and usually need replacing.
NAC is one part of a Zero Trust approach: it identifies devices and limits what each can reach at the network level. Zero Trust also covers user identity, device health and access to individual applications, which NAC does not do on its own. Cyber Essentials does not require NAC. It helps by showing what is connected and keeping unmanaged devices in a separate segment, but the five controls still have to be met on the devices themselves.
Yes, and it is the approach I recommend. Visibility can be switched on across every site at once, because it changes nothing. Enforcement is then introduced site by site, and within a site, segment by segment. Starting with the simplest site means the design and the rollback procedure are proven before they reach the busiest location.

Planning a NAC rollout?

I design and deploy network access control as part of wider Fortinet and network security work: audit first, visibility before enforcement, and documentation someone else can run. Utilis is independent and does not resell hardware or licences. Get in touch or book a 30-minute call and bring your network diagram.

Book a Free Discovery Call