Portnox

Plans & Pricing

Universal zero trust that reduces breach risk by 75% and delivers 287% ROI.

Network 
Authentication (RADIUS)

Spin up our cloud RADIUS service & unlock powerful zero trust network authentication.

Network

Access Control (NAC)

All of the advantages of RADIUS plus full-fledged zero trust NAC for distributed environments.

Zero Trust

Network Access (ZTNA)

Fast, frictionless ZTNA that users will love and security teams can trust.

tacacs logo

Network Device
Administration
(TACACS+)

Keep security auditors off your back with cloud
TACACS+ / AAA Services.

universal zero trust portnox

Universal
Zero Trust
(Full Platform)

Leverage all of the critical zero trust features of the Portnox Cloud in one unified solution.

Volume discounts available for all products.

Product Features

Header about product features here.

Feature

RADIUS

RADIUS

NAC

NAC

ZTNA

ZTNA

Universal Zero Trust

UAC

Authentication Services

Wireless, wired, VPN access

Check Mark
Check Mark
Check Mark

Anti-flood protection services

Check Mark
Check Mark
Check Mark

RadSec support

Check Mark
Check Mark
Check Mark

RADIUS forwarding rules (eduroam support)

Check Mark
Check Mark
Check Mark

Role-based authentication

Check Mark
Check Mark
Check Mark
Check Mark

MAC authentication bypass

Check Mark
Check Mark
Check Mark

Account lifecycle synchronization

Check Mark
Check Mark
Check Mark
Check Mark

Passwordless authentication

Check Mark
Check Mark
Check Mark

Certificate authority services

$1 / device

Check Mark
Check Mark
Check Mark

SAML 2.0 authentication services

Check Mark
Check Mark

OpenID Connect

Check Mark
Check Mark

RADIUS

NAC

ZTNA

UZT

Wireless, wired, VPN access

Check Mark
Check Mark
Check Mark

Anti-flood protection services

Check Mark
Check Mark
Check Mark

RadSec support

Check Mark
Check Mark
Check Mark

RADIUS forwarding rules (eduroam support)

Check Mark
Check Mark
Check Mark

Role-based authentication

Check Mark
Check Mark
Check Mark
Check Mark

MAC authentication bypass

Check Mark
Check Mark
Check Mark

Account lifecycle synchronization

Check Mark
Check Mark
Check Mark
Check Mark

Passwordless authentication

Check Mark
Check Mark
Check Mark

Certificate authority services

$1 / device

Check Mark
Check Mark
Check Mark

SAML 2.0 authentication services

Check Mark
Check Mark

OpenID Connect

Check Mark
Check Mark

Gain access to all of Portnox's powerful zero trust access control free capabilities for 30 days!

See all features →

802.1X authentication

Dynamic VLAN / ACL assignment

Portnox AgentP

Check Mark

Agentless posture assessment

Check Mark

Continuous endpoint risk & posture assessment

Policy enforcement & automated remediation

Audit tracking & logging

Agentless remote access

Split tunneling

SSL offloading

Digital experience monitoring (DEX)

Secure SaaS application access (CASB)

Secure access to on-prem applications

Application specific risk profiles

IP geo restrictions to SaaS & hosted applications

RADIUS

NAC

ZTNA

UZT

802.1X authentication

Dynamic VLAN / ACL assignment

Portnox AgentP

Check Mark

Agentless posture assessment

Check Mark

Continuous endpoint risk & posture assessment

Policy enforcement & automated remediation

Audit tracking & logging

Agentless remote access

Split tunneling

SSL offloading

Digital experience monitoring (DEX)

Secure SaaS application access (CASB)

Secure access to on-prem applications

Application specific risk profiles

IP geo restrictions to SaaS & hosted applications

Gain access to all of Portnox's powerful zero trust access control free capabilities for 30 days!

See all features →

Guest accounts

Up to 50 guests per day

Up to 100 guests per day

Self-onboarding for guests

Check Mark
Check Mark

Sponsor-based onboarding

Check Mark
Check Mark

SMS-based onboarding

Check Mark
Check Mark

RADIUS

NAC

ZTNA

UZT

Guest accounts

Up to 50 guests per day

Up to 50 guests per day

Self-onboarding for guests

Check Mark
Check Mark

Sponsor-based onboarding

Check Mark
Check Mark

SMS-based onboarding

Check Mark
Check Mark

Gain access to all of Portnox's powerful zero trust access control free capabilities for 30 days!

See all features →

Role-based access policies

Check Mark
Check Mark
Check Mark
Check Mark

Location-based policies

Check Mark
Check Mark
Check Mark
Check Mark

Change of Authorization (CoA)

Check Mark
Check Mark
Check Mark

Device access geo restrictions

Check Mark
Check Mark
Check Mark

RADIUS

NAC

ZTNA

UZT

Role-based access policies

Check Mark
Check Mark
Check Mark
Check Mark

Location-based policies

Check Mark
Check Mark
Check Mark
Check Mark

Change of Authorization (CoA)

Check Mark
Check Mark
Check Mark

Device access geo restrictions

Check Mark
Check Mark
Check Mark

Gain access to all of Portnox's powerful zero trust access control free capabilities for 30 days!

See all features →

Monitoring-only mode

Check Mark
Check Mark
Check Mark

Archived devices data retention

14 days

45 days

30 days

60 days

Dynamic group assignment per device type

Check Mark
Check Mark
Check Mark

IoT profiling

Check Mark
Check Mark
Check Mark

IoT device trust

Check Mark
Check Mark

RADIUS

NAC

ZTNA

UZT

Monitoring-only mode

Check Mark
Check Mark
Check Mark

Archived devices data retention

14 days

45 days

30 days

60 days

Dynamic group assignment per device type

Check Mark
Check Mark
Check Mark
Check Mark

IoT profiling

Check Mark
Check Mark
Check Mark

IoT device trust

Check Mark
Check Mark

Gain access to all of Portnox's powerful zero trust access control free capabilities for 30 days!

See all features →

Intune integration for advanced device properties

Check Mark
Check Mark
Check Mark

Jamf integration for advanced device properties

Check Mark
Check Mark
Check Mark

Crowdstrike integration for advanced device properties

Check Mark
Check Mark
Check Mark

SentinelOne integration for advanced device properties

Check Mark
Check Mark
Check Mark

RADIUS

NAC

ZTNA

UZT

Intune integration for advanced device properties

Check Mark
Check Mark
Check Mark

Jamf integration for advanced device properties

Check Mark
Check Mark
Check Mark

Crowdstrike integration for advanced device properties

Check Mark
Check Mark
Check Mark

SentinelOne integration for advanced device properties

Check Mark
Check Mark
Check Mark

Gain access to all of Portnox's powerful zero trust access control free capabilities for 30 days!

See all features →

Onboarding services

Check Mark
Check Mark
Check Mark
Check Mark

Device provisioning services

Check Mark
Check Mark
Check Mark
Check Mark

Certificate enrollment services

Check Mark
Check Mark
Check Mark
Check Mark

RADIUS

NAC

ZTNA

UZT

Onboarding services

Check Mark
Check Mark
Check Mark
Check Mark

Device provisioning services

Check Mark
Check Mark
Check Mark
Check Mark

Certificate enrollment services

Check Mark
Check Mark
Check Mark
Check Mark

Gain access to all of Portnox's powerful zero trust access control free capabilities for 30 days!

See all features →

RADIUS proxy - local failover

Check Mark
Check Mark
Check Mark

Multi-regional redundancy

Check Mark
Check Mark
Check Mark

TACACS+ / AAA

1 admin / 100 devices

2 admin / 200 devices

1 admin / 100 devices

3 admin / 300 devices

SIEM

On prem/SaaS

On prem/SaaS

On prem/SaaS

On prem/SaaS

MFA admin access (w/ SMS)

Check Mark
Check Mark
Check Mark

MFA admin access (w/ Authenticator App)

Check Mark
Check Mark
Check Mark

RESTful API

Check Mark
Check Mark
Check Mark

Entra (Azure) AD/Google Workspace/Active Directory

Check Mark
Check Mark
Check Mark
Check Mark

Okta

Check Mark
Check Mark
Check Mark

Extended device data retention

Add 30 days – 99¢ / device / year

Each additional 30 days – 99¢ / device / year

Add 30 days – 99¢ / device / year

Each additional 30 days – 99¢ / device / year

24x7x365 Support

Priority One Issues*

Priority One Issues*

Priority One Issues*

Priority One Issues*

Community Support

Check Mark
Check Mark
Check Mark
Check Mark

RADIUS

NAC

ZTNA

UZT

RADIUS proxy - local failover

Check Mark
Check Mark
Check Mark

Multi-regional redundancy

Check Mark
Check Mark
Check Mark

TACACS+ / AAA

1 admin / 100 devices

2 admin / 200 devices

1 admin / 100 devices

3 admin / 300 devices

SIEM

On prem/SaaS

On prem/SaaS

On prem/SaaS

On prem/SaaS

MFA admin access (w/ SMS)

Check Mark
Check Mark
Check Mark

MFA admin access (w/ Authenticator App)

Check Mark
Check Mark
Check Mark

RESTful API

Check Mark
Check Mark
Check Mark

Entra (Azure) AD/Google Workspace/Active Directory

Check Mark
Check Mark
Check Mark
Check Mark

Okta

Check Mark
Check Mark
Check Mark

Extended device data retention

Add 30 days – 99¢ / device / year45 days

Each additional 30 days – 99¢ / device / year

Add 30 days – 99¢ / device / year

Each additional 30 days – 99¢ / device / year

24x7x365 Support

Priority One Issues*

Priority One Issues*

Priority One Issues*

Priority One Issues*

Community Support

Check Mark
Check Mark
Check Mark
Check Mark

Gain access to all of Portnox's powerful zero trust access control free capabilities for 30 days!

See all features →

Extended guest package (50)

Additional SMS package (1000)

TACACS+ / AAA

RADIUS

NAC

ZTNA

UZT

Extended guest package (50)

Additional SMS package (1000)

TACACS+ / AAA

Gain access to all of Portnox's powerful zero trust access control free capabilities for 30 days!

See all features →

Optional

Add-on packs available:

for RADIUS, NAC, and UAC/Cloud

Gain access to all of Portnox’s tools!

Extended Guest Package (50)

Extended Guest Package (50)

Extended Guest Package (50)

Universal zero trust. All from the cloud. No BS.

FAQs

General

Subscription terms are available in 12, 24, and 36 months. Additional discounts are available for terms longer than 12 months.

Yes, please contact Sales for information on volume discounts that may be applicable to you and your organization.

Absolutely! Not only is it possible, it is also how most customers deploy Portnox in their environments.

We strive to ensure that you have the absolute best possible onboarding experience, regardless of which package you may purchase. However, some organizations may need some additional assistance or maybe don’t have time to invest in configuring a zero trust access control solution. If you require additional onboarding assistance, please contact our sales department. They can help you determine what is the best onboarding tier for your needs.

Yes. Portnox provides special educational discounts for qualifying K-12 and higher education institutions. Please contact Sales for more information.

Yes. Portnox Cloud RADIUS is deployed globally with high availability and low latency in mind. RADIUS servers are available across multiple continents, ensuring optimal performance and compliance for organizations worldwide.

Server regions include:

  • United States
  • Europe
  • Asia/Pacific

This geographic distribution supports compliance with data residency requirements and delivers high-speed authentication responses regardless of user or device location.

RADIUS

No. Portnox’s cloud RADIUS is just that – fully cloud-native, and can be deployed at scale directly through the platform without needing any additional hardware to be installed on-site.

Today, users can integrate Azure Active Directory and Microsoft Active Directory with Portnox RADIUS. The Portnox Cloud also boasts its own proprietary directory should you not currently utilize one of these services.

Relying on the IEEE 802.1X authentication protocol, Portnox RADIUS offers role-based authentication and MAC Authentication Bypass (MAB) as standard authentication options. The solution also offers account lifecycle synchronization out-of-the-box.

Absolutely! Thanks to our innovative IoT fingerprinting, we can identify over 260,000 unique IoT devices across 27,000 different brands with more being added daily. We use a variety of methods including MAC address clustering and DHCP gleaning, along with our new SaaS-based DHCP listener to quickly and accurately identify all of the devices on your network.

Yes. Portnox Cloud allows customers to leverage our multiple RADIUS servers deployed in different geographic regions of the world. Alternatively, we provide an optional Local RADIUS instance that customers can deploy on-prem or in their private cloud to provide an additional level of redundancy. Portnox Cloud can also be used as a RADIUS proxy for services such as eduroam.

NAC

Portnox supports key aspects of zero trust:

  • Identity: Seamless integration with identity providers like Okta and Azure along with our own proprietary directory service
  • Endpoints: Continuous risk posture assessment and automated endpoint remediation
  • Data: Through the use of the IEEE 802.1X authentication protocol, Portnox protects all data traveling from various platform components to and from the system’s cloud services.
  • Network: Access control enforcement across wired, wireless and VPN access layers
  • Infrastructure: TACACS+ enables transparent and secure administration of network devices with centralized user authentication.

Portnox provides access control enforcement across wired, wireless, and VPN access layers.

Several unique features give Portnox the edge above other NAC solutions. Specifically continuous risk assessment and remediation allows your IT team to keep unprotected devices quarantined or off the network entirely. Risk posture is continuously evaluated, so any changes to the device are detected and acted upon quickly.

Also our innovative approach to IoT fingerprinting gives you a complete picture of what devices are lurking on your network that you may not be aware of. And finally, our cloud-based, vendor agnostic platform means you will be able to control access for all your devices without leaving anything unprotected because it doesn’t work with a more traditional, vendor-specific solution.

Absolutely! Portnox Cloud integrates directly with 3rd party solutions such as Microsoft’s inTune to agentlessly assess the device’s compliance state prior to granting the device access to the network. Noncompliant devices can optionally be granted limited access to a quarantine or remediation VLAN where typically access is restricted only to resources necessary to bring the device back into compliance.

Portnox’s Cloud API is a RESTful endpoint documented in Swagger. This API is leveraged by customers to automate allows customers to automate routine tasks, such as adding MAC Addresses to a MAB account, Portnox Cloud supports all common CRUD (Create Read Update Delete) for devices, accounts, NASs, and sites.

ZTNA

Portnox ZTNA is cloud-native, passwordless, agentless, and clientless. Unlike VPNs, it doesn’t tunnel traffic or require endpoint software. It enables direct, policy-based access to apps without compromising user experience or security.

Nope! Portnox’s lightweight AgentP is optional, but not required. ZTNA can be run agentless, which means users can connect securely without installing anything extra—reducing friction and IT overhead.

Every access attempt is evaluated in real time. Portnox checks device posture (e.g., OS version, endpoint protection, encryption) before granting access. Non-compliant devices are blocked or guided through automated remediation.

Yes. Portnox ZTNA provides secure remote access to cloud and on-prem apps—without the latency, maintenance, or security risks of VPNs.

Yes. It uses certificate-based authentication to eliminate the need for usernames and passwords—protecting users from phishing and credential theft.

TACACS+

Each TACACS+ license entitles you to one TACACS+ user and 100 TACACS+ devices. To determine which license size you need, simply count the number of TACACS+ users in your organization who will be accessing TACACS+ capable devices, such as switches, routers, etc. Then multiply that number by 100. If that number is less than the total number of TACACS+ capable devices, than take the total number of TACACS+ devices and divide by 100. This will give you the total number of TACACS+ licenses you will need to cover your environment.

Portnox TACACS is a cloud-based service which is administrated, configured, and managed through our Portnox Cloud SaaS portal. A virtual appliance is downloaded and deployed in one or more locations on your network. This virtual appliance can be deployed on Microsoft Hyper-V, VMware, or any hypervisor which supports the import of OVA or VMDK filetypes, such as Nutanix Acropolis, Citrix XenServer, Oracle VirtualBox, Proxmox, KVM, Parallels, etc.
Not at all. TACACS+ is supported by a very wide range of vendors and devices, not just Cisco. Just a few of the vendors that support TACACS+ include Dell, Juniper, F5, Extreme Networks, Brocade, HP/Aruba, Alcatel-Lucent, Adtran, Ciena, AVI Networks, Citrix NetScaler, Ribbon Communications, Samsung, Fortinet, Fujitsu, Huawei, Netgear, Palo Alto Networks, CommScope, and Orolia SecureSync, to name only a few.
While a large number of network equipment vendors support TACACS+, there are a variety of applications, appliances, and operating systems that also support TACACS+. Some examples include Linux, BlueCat Address Manager, InfoBlox, IBM NetCool, Radware APSolute, AppViewX, Oracle Enterprise Session Border Controller, Trendmicro TippingPoint, Avocent Cyclades and many others.
Designed to Scale With You

We want our partners to grow their businesses alongside us.

Our partners are an extension of our business. As such, Portnox’s Partner Program offers special pricing and incentives designed to award those partners committed to achieving our shared goal of securing network access for more and more companies around the world.

Don't take our word for it

Leading the way

Portnox Now Supports Access Control for Console-Based Apps with ZTNA

X