Captive Portal

Secure, self-service guest Wi-Fi access with flexible verification, centralized management, and complete session auditing.

  • Get guests online in minutes
  • Keep your corporate network secure
  • Flexible guest verification options
  • Track every session
  • No on-prem appliances required
portnox captive portal wifi security

Guests online in seconds, at every site, on any Wi-Fi - with nothing to install.

Scalable, secure guest access without the IT tickets

Stand up a guest Wi-Fi network in minutes. SMS verification, sponsored access, or admin-issued credentials — pick the flow that fits each location and let guests onboard themselves from any device, with nothing to install. Captive Portal carries your logo and a customizable acceptable-use statement; your front desk stops playing helpdesk, and your IT team gets valuable time back.  

  • Wi-Fi onboarding for guest devices — nothing to install 
  • Four authentication flows: sponsored guest, SMS self-registration, disclaimer-only, or admin-issued credentials 
  • Branded portal: your logo plus a customizable acceptable-use statement guests accept before connecting 
  • Works with your existing Wi-Fi — many major wireless vendors supported out of the box (see Integrations) 
  • A dedicated Guest Admin role lets front-desk staff manage guest accounts — with zero access to NAC policy or network configuration. 

A single platform for guest access management

When guest access lives in your Wi-Fi controller, every site is its own island — separate configs, separate rules, separate blind spots. Define a guest policy once and enforce it across every location and wireless vendor. See, extend, expire, and revoke any guest session across your entire footprint from a single console. 

  • One guest policy workflow, enforced identically across all sites and SSIDs 
  • Vendor-agnostic: manage every captive portal together, regardless of which wireless vendor runs each guest SSID 
  • Central, live visibility into every guest session 
  • Same platform and console as employee NAC, BYOD, and IoT policy — guests and employees managed together for greater flexibility, security, and scalability 
portnox captive portal

Guest access accountability and isolation, by design

“Who was on our network, when, and what could they reach?” With Portnox, that’s not a research project. Every guest session is authorized, time-boxed, and isolated from corporate systems. Sponsor approvals and denials are logged; terms-of-use acceptance is captured at connection, and access expires on schedule — no manual cleanup required. 

  • Identity-bound sessions for sponsored, SMS, and admin-issued guests — accountability for granted access, not blanket anonymity 
  • Sponsor approval and denial logged— know who approved guest access, and when 
  • Dynamic session timeout: set how long a guest session stays valid, with automated expiration and no manual cleanup required. On select NAS vendors (Mist, WatchGuard, UniFi), expiration syncs directly to the controller 
  • Acceptable-use / disclaimer acceptance captured at connection 
  • Network that keeps guests isolated from internal systems and data 

Bring your own Wi-Fi. We'll bring the platform control.

No rip-and-replace. Portnox plugs into your existing wireless infrastructure and manages every portal, policy, and session centrally from the cloud, even across mixed-vendor estates. Same platform, one less system to babysit. 

cisco-white-logo-transparent
HPEAruba_Logo_Orange_Rev
RUCKUS-Networks-Endorsed-Logo_White
EXTREME_Networks.png
JUNIPER_BIG.D-3e98987b.png
Fortinet-logo-rgb-white-768x212
ubiquiti-white-logo-1024x309-1-300x143
Watchguard_logo-white

+ more

Built for how your industry hosts

Healthcare

Patients, families, and visiting clinicians expect Wi-Fi; HIPAA expects separation. Give visitors seamless access while keeping clinical systems and PHI segmented — with the audit trail to prove it. 

Retail & Hospitality

Guest Wi-Fi is part of the brand experience — instant onboarding across every store or property while keeping payment environments cleanly segmented. 

Education

Campus visitors, events, applicants, and a sea of unmanaged devices. Standardize visitor access across every building and campus without adding helpdesk tickets or shared passwords. 

Not every guest portal is access control

Feature Wi-Fi vendor portals Guest Wi-Fi marketing tools Portnox Captive Portal
What it really is A splash page bundled with hardware Access traded for data — connect only after opting into marketing capture, social login, or analytics tracking. Guest access, native to a unified access control platform
Policy & identity Per-controller config, session-based Access traded for identity, guests connect only after handing over their data Access granted, no data trade required.
Visibility & audit Per-site, fragmented Marketing analytics, not audit trails Every session, every site, one audit trail

Don't take our word for it

Schedule a 
Portnox demo with an expert today.

Request a Portnox demo today and discover the many capabilities of our cloud-native zero trust access control and security platform.

Captive Portal

FAQs

The Portnox Captive Portal is used to control access to your wireless guest guest network. Once configured, users trying to connect to your guest network will be redirected to and authenticated by the Portnox Captive Portal web application.  

Note: The Portnox RADIUS service must be enabled to use the Portnox captive portal service.

Portnox Cloud delivers guest access by redirecting visitors who join your dedicated guest SSID to a cloud-hosted captive portal, where they verify their identity through self-registration, sponsor approval, or admin-issued credentials before any network access is granted. Once authenticated, guests receive time-limitedaccess on the guest network only, fully isolated from your corporate network while giving IT complete visibility and an audit trail of every connection.

Yes, with three of the four authentication options. SMS authentication and disclaimer-only access are fully self-service. With these options guests can either verify via a text-message code or simply accept the terms. Sponsored Guest requires approval from any employee (not IT) via email confirmation. Only the Portnox Cloud Guest option involves IT for each guest, as an administrator must manually create and deliver the credentials delivering added control

No. The Captive Portal itself is fully agentless guests authenticate and accept your acceptable-use policy directly in the browser, with nothing downloaded or installed at any point. (BYOD devices that need certificate-based network access rather than guest-style browser access can use Portnox Connect (Windows only), which also leaves nothing permanently installed — see how it works here.

The Portnox Cloud captive portal supports the following Wi-Fi controllers: Cisco, Cisco Meraki, HPE Aruba, RUCKUS Networks ZoneDirector and SmartZone, Juniper Mist, Extreme WiNG, Aerohive (legacy, now Extreme), Fortinet, Ubiquiti UniFi, and WatchGuard. Because there is no universal standard for captive portals, guest access requires one of these supported controllers — step-by-step integration guides for each are available in our documentation. 

Yes. Guest management in Portnox Cloud is platform-independent, so you can manage multiple captive portals centrally regardless of which Wi-Fi controllers run the guest SSIDs at each site — the same portal, branding, authentication method, and session policies can apply everywhere. A single tenant supports multiple captive portal configurations, so you can also standardize on one portal globally or vary the experience by region or location type as needed.

Portnox Cloud keeps guest traffic on a dedicated SSID that is fully isolated from your corporate network, supporting the network segmentation PCI DSS requires to keep untrusted devices away from cardholder data environments. Every guest is individually identified and authenticated rather than sharing a generic password, and all access is time-limited, policy-controlled, and logged — giving you the audit trail to demonstrate that untrusted devices never touch in-scope systems.

Yes, access auto-expires: the Dynamic session timeout setting defines how long a guest session and account remain valid, and once it ends, the guest account is automatically deleted and the guest must re-authenticate through Captive Portal to reconnect. Best practice is to match the timeout to the visit — hours for day visitors, longer if needed — and note that for Mist, WatchGuard, and UniFi, Portnox syncs the expiration to the controller automatically, while other vendors require setting a matching session expiration on the controller side.

Guest access is short-term, policy-scoped Wi-Fi for visitors, contractors, and other non-employee users granted through the Captive Portal via self-registration, sponsorship, or admin-issued credentials, and automatically expired by policy. BYOD is different: it’s an authorized user’s personal device getting ongoing, certificate-based network access rather than a one-time guest session. For BYOD devices on Windows, Portnox Connect automates that certificate-based setup in a single run, with nothing left installed afterward. Note: Connect requires a standard Portnox account — it cannot be used with contractor accounts, so external contractors who need this path should be provisioned as standard accounts instead.

Contact Portnox Sales for pricing.

No, Captive Portal governs access to the network for guests, contractors, and BYOD devices alike — the branded portal, the policy engine, the audit trail. It’s not the mechanism that gets a specific personal device its network certificate and adapter configuration in the first place; for Windows BYOD devices, that’s what Portnox Connect automates.

Related Reading

Webinars

The Identity Blind Spot: Why AI Agents Are the Access Control Gap Security Teams Aren’t Ready For

Product Briefs

Portnox Cloud Platform Overview

PCI DSS

Portnox Cloud PCI DSS Shared Responsibility Matrix

Leading the way