Network And System Security Engineer at a financial services firm with 10,001+ employees
Real User
Top 20
Jul 25, 2026
Portnox was primarily used for network access control, which granted access to enterprise devices based on specific parameters that we set. A specific example of how I used Portnox for network access control in my environment involved network devices and enterprise devices that did not meet specific criteria. For instance, if a device was no longer joined to the domain, even if it was an enterprise device, and had lost trust with the domain, it would not be able to connect to the network. In such cases, the device owner would need to reach out to me or to the local IT support representative for the branch to obtain temporary access so that the device could be joined to the domain to regain trust, and then it would resume normal operation. That was the primary use case. Regarding my main use case with Portnox, it was used because we were in the setup phase when I started using it. It was an ongoing project, and it was primarily focused on network access control. It functioned effectively.
Portnox serves as my primary solution for network access control and zero trust security. I use it to authenticate users and devices before they connect to the network, monitor endpoint compliance, and enforce security policies based on user identity and device posture. My main use case for Portnox is securing network access through zero trust principles. It authenticates users and devices, enforces compliance policies, provides visibility into connected endpoints, and automatically restricts access for non-compliant or unauthorized devices. This helps strengthen network security, support BYOD environments, and simplify access control management across the organization.
I mainly use Portnox to instantly isolate a compromised or non-compliant endpoint from the rest of the network the moment a threat or vulnerability is detected. Portnox's main use case is for authentication, posture assessment, enforcement, and segmentation, using a cloud-native identity provider such as Azure AD or Entra ID to verify that the person attempting to log in is actually an active employee with the right credentials or digital certifications. It functions as a security verification tool that we use. A recent and highly impacted scenario that stands out occurred during a critical availability window when a new zero-day operating system vulnerability was actively being exploited across the industry. As I work in healthcare IT infrastructure, maintaining zero trust network integrity is paramount because a single compromised endpoint can act as a lateral entry point to critical patient care applications or medical databases. We had a corporate laptop belonging to an off-shift employee that missed the mandatory security patch cycle via our MDM tool, Intune. The user attempted to log into the corporate network via VPN from home while the device was still out of compliance. As soon as the connection request hit our gateway, Portnox performed an automated posture assessment rather than simply checking if the user's active credentials were correct. Portnox verified the machine's configuration against our updated compliance policies, instantly flagging it as missing critical security patches, having an altered local firewall configuration, and an out-of-date endpoint security agent. Once Portnox flagged the device as non-compliant and automatically moved it into isolated quarantine, our team initiated a coordinated response between incident management, the security operational centers (SOC), and our endpoint engineering teams to remedy the issue without compromising the wider network. The specific step-by-step actions we took included incident logging and alert verification followed by safe communication with the quarantine zone, then forced remediation and policy synchronization, ensuring the device was safely coordinated in quarantine with minimal risk of lateral threat movement. Our team executed several technical steps, triggering a forced evaluation cycle from our MDM platform to push mission-critical OS security patches directly to the device, and remotely initiating a manual update script to force the device's local antivirus and EDR definitions to sync with the latest cloud signatures. The final step involved reassessment and automatic return to production. Portnox's AI has been exceptionally accurate and reliable, especially regarding fingerprinting random IoT or unmatched devices on the network. Previously, with older systems, we experienced many false positives, misidentifying corporate machines, but Portnox very rarely makes mistakes. The risk tooling is dependable, and when machine learning modules flag diverse behavior as risky, there is always a valid technical reason behind it, making Portnox an automated tool we trust to run on autopilot without constant false alarms disrupting user speed.
Some of the best features that I have experienced with Portnox is the integration with identity providers and the fact that they introduced ZTNA. Recently, they introduced session recording, which was one of the recommendations we had posted to them. So I would say ZTNA and the identity integration, and of course the general NAC itself, the network access control. Portnox can be deployed both as an on-cloud and on-premises solution. You can go for the on-premise version that is fully on-premise and fully controlled by the customer, and then there's the cloud, the SaaS, which is also another solution, the CLEAR and the CORE. So it can be either. The cloud version of Portnox is on Azure as they are partners with Azure. For the on-premise, it is a Windows-based deployment.
From customer to customer, the use case for Portnox is different. Some customers ask for a network to protect their board and local network, while others want to allow employees to access via VPN and for authentication to connect remotely to their network. Portnox unified access control platform is necessary for any huge company with lots of branches where they don't know who can access their systems. For example, I installed it for customers such as an airline company, and for them, it is important. It is for specific customers, not for everyone, but in general, it is amazing. Conditional access functions similar to a VLAN, and you can give every customer their own network so it will be separate from others. Employees in an administration department do not need to be allowed to see other networks or access networks that they do not belong to.
My use case for Portnox is for whitelisting ports and adding policies. We are using two modes: enforce mode and monitoring mode. For monitoring, we are using some smaller switches, just some business switches and some others. For enforce, we use some critical switches, such as those for security purposes and highly secure switches in the manufacturing sector for security purposes only. For unused port features that we do not monitor, we do not disable the port. This has increased our security. Integrating Portnox with our existing identity providers like Azure AD, Okta, and Google Workspace does have some server considerations. In our organization, we are using four clusters. Between those four clusters, we separate all the users. I am not sure about the server configuration. We have server configuration files maintained by the server team separately. We just do some email configurations and user-level configurations. I have used Portnox conditional access by using the resident groups only for separating the network and a separate data center, and some other groups are there. We mostly use the networking groups. For small switches, we will not enable the policies together because for a small switch, we just move those switches to monitoring mode. That is why these policies are enabled.
I have predominantly used Portnox as a NAC solution for centralized, cloud-managed access control across our globally distributed data centers and offices, with more emphasis on offices than data centers. I integrated it with Microsoft Entra ID, on-premises LDAP servers, and JumpCloud to consume identities. I configured vendor-specific attributes, network access devices including Cisco, Ubiquiti UniFi Wi-Fi, and Aruba access points, and set up 802.1X authentication, access policies, and segmentation policies. This is my primary use case. I have less experience using it for zero trust purposes, as we have always used other tools and did not want to rely on something hosted in the cloud.
Information Technology System Administrator at a energy/utilities company with 10,001+ employees
Real User
Top 20
Apr 11, 2025
My initial use case for Portnox was as an on-prem solution that we used for network access control. We implemented ISO 27001 around that period, and Portnox served as our network access control. It helped in locking our ports where unauthorized users or devices in the environment were blocked. It worked pretty efficiently for us. The last time I used Portnox was earlier this year because I just moved roles. Where I am now, I've recommended that Portnox be implemented, which is currently under review. We might contact the vendor for a PoC, but it's something that I know works and has helped me significantly in terms of network access control.
Systems Analyst at a construction company with 1,001-5,000 employees
Real User
Top 10
Nov 25, 2024
We use it for dynamic VLAN assignment and for NAC, so network access control, to manage any external devices or internal devices that connect to our network. It auto-assigns them to the correct groups or VLANs.
Technical Sales / Presales at Routelink Integrated Systems
Reseller
Dec 29, 2023
I work at an IT firm where a couple of our end customers either use the product or want to onboard it in their environment. As a process engineer, I have to take care of certain presentations and discuss the deployment process with our company's customers. Some of our company's customers who use Portnox CORE's on-premises version found it to not be suitable for their usage or use cases. Later on, my company started to push Portnox Clear over Portnox CORE. Portnox Clear is a cloud-based solution, so our company's customers need not worry about deployment and other related areas regarding the product. Based on my own experience, I always encourage people to opt for Portnox Clear so that they don't have to worry about deployment and installation areas. One of our company's customers has an electricity distribution business with a lot of branches across the country, because of which they need to deal with a lot of connected devices. For our company's customer who deals in the electricity distribution business, I monitor routers and access points across the country, ensuring that no unauthorized sources are connected to them while ensuring the configuration and features of the product are accurate and up to date.
Information Security Officer at a financial services firm with 1,001-5,000 employees
Real User
May 31, 2022
Our aim is to ensure compliance, so we use this solution for network access control, where we define the threshold for endpoint compliance. This extends to the Wireless LAN, which ensures that whatever compliance structure has been defined is maintained. We have many users working remotely, so we use Portnox to provide a high level of assurance. I'm an information security officer and we are customers of Portnox.
Portnox NAC is a cloud-native network access control solution built for today's hybrid, distributed enterprises. Get real-time visibility into every device on your network, enforce risk-based access policies automatically, and maintain continuous compliance — all without deploying a single on-premises appliance.
----------
About Portnox Security
Portnox is a cloud-native enterprise access control provider that helps organizations secure every identity - human and non-human - across networks,...
Portnox was primarily used for network access control, which granted access to enterprise devices based on specific parameters that we set. A specific example of how I used Portnox for network access control in my environment involved network devices and enterprise devices that did not meet specific criteria. For instance, if a device was no longer joined to the domain, even if it was an enterprise device, and had lost trust with the domain, it would not be able to connect to the network. In such cases, the device owner would need to reach out to me or to the local IT support representative for the branch to obtain temporary access so that the device could be joined to the domain to regain trust, and then it would resume normal operation. That was the primary use case. Regarding my main use case with Portnox, it was used because we were in the setup phase when I started using it. It was an ongoing project, and it was primarily focused on network access control. It functioned effectively.
Portnox serves as my primary solution for network access control and zero trust security. I use it to authenticate users and devices before they connect to the network, monitor endpoint compliance, and enforce security policies based on user identity and device posture. My main use case for Portnox is securing network access through zero trust principles. It authenticates users and devices, enforces compliance policies, provides visibility into connected endpoints, and automatically restricts access for non-compliant or unauthorized devices. This helps strengthen network security, support BYOD environments, and simplify access control management across the organization.
I mainly use Portnox to instantly isolate a compromised or non-compliant endpoint from the rest of the network the moment a threat or vulnerability is detected. Portnox's main use case is for authentication, posture assessment, enforcement, and segmentation, using a cloud-native identity provider such as Azure AD or Entra ID to verify that the person attempting to log in is actually an active employee with the right credentials or digital certifications. It functions as a security verification tool that we use. A recent and highly impacted scenario that stands out occurred during a critical availability window when a new zero-day operating system vulnerability was actively being exploited across the industry. As I work in healthcare IT infrastructure, maintaining zero trust network integrity is paramount because a single compromised endpoint can act as a lateral entry point to critical patient care applications or medical databases. We had a corporate laptop belonging to an off-shift employee that missed the mandatory security patch cycle via our MDM tool, Intune. The user attempted to log into the corporate network via VPN from home while the device was still out of compliance. As soon as the connection request hit our gateway, Portnox performed an automated posture assessment rather than simply checking if the user's active credentials were correct. Portnox verified the machine's configuration against our updated compliance policies, instantly flagging it as missing critical security patches, having an altered local firewall configuration, and an out-of-date endpoint security agent. Once Portnox flagged the device as non-compliant and automatically moved it into isolated quarantine, our team initiated a coordinated response between incident management, the security operational centers (SOC), and our endpoint engineering teams to remedy the issue without compromising the wider network. The specific step-by-step actions we took included incident logging and alert verification followed by safe communication with the quarantine zone, then forced remediation and policy synchronization, ensuring the device was safely coordinated in quarantine with minimal risk of lateral threat movement. Our team executed several technical steps, triggering a forced evaluation cycle from our MDM platform to push mission-critical OS security patches directly to the device, and remotely initiating a manual update script to force the device's local antivirus and EDR definitions to sync with the latest cloud signatures. The final step involved reassessment and automatic return to production. Portnox's AI has been exceptionally accurate and reliable, especially regarding fingerprinting random IoT or unmatched devices on the network. Previously, with older systems, we experienced many false positives, misidentifying corporate machines, but Portnox very rarely makes mistakes. The risk tooling is dependable, and when machine learning modules flag diverse behavior as risky, there is always a valid technical reason behind it, making Portnox an automated tool we trust to run on autopilot without constant false alarms disrupting user speed.
Some of the best features that I have experienced with Portnox is the integration with identity providers and the fact that they introduced ZTNA. Recently, they introduced session recording, which was one of the recommendations we had posted to them. So I would say ZTNA and the identity integration, and of course the general NAC itself, the network access control. Portnox can be deployed both as an on-cloud and on-premises solution. You can go for the on-premise version that is fully on-premise and fully controlled by the customer, and then there's the cloud, the SaaS, which is also another solution, the CLEAR and the CORE. So it can be either. The cloud version of Portnox is on Azure as they are partners with Azure. For the on-premise, it is a Windows-based deployment.
From customer to customer, the use case for Portnox is different. Some customers ask for a network to protect their board and local network, while others want to allow employees to access via VPN and for authentication to connect remotely to their network. Portnox unified access control platform is necessary for any huge company with lots of branches where they don't know who can access their systems. For example, I installed it for customers such as an airline company, and for them, it is important. It is for specific customers, not for everyone, but in general, it is amazing. Conditional access functions similar to a VLAN, and you can give every customer their own network so it will be separate from others. Employees in an administration department do not need to be allowed to see other networks or access networks that they do not belong to.
My use case for Portnox is for whitelisting ports and adding policies. We are using two modes: enforce mode and monitoring mode. For monitoring, we are using some smaller switches, just some business switches and some others. For enforce, we use some critical switches, such as those for security purposes and highly secure switches in the manufacturing sector for security purposes only. For unused port features that we do not monitor, we do not disable the port. This has increased our security. Integrating Portnox with our existing identity providers like Azure AD, Okta, and Google Workspace does have some server considerations. In our organization, we are using four clusters. Between those four clusters, we separate all the users. I am not sure about the server configuration. We have server configuration files maintained by the server team separately. We just do some email configurations and user-level configurations. I have used Portnox conditional access by using the resident groups only for separating the network and a separate data center, and some other groups are there. We mostly use the networking groups. For small switches, we will not enable the policies together because for a small switch, we just move those switches to monitoring mode. That is why these policies are enabled.
My use case for Portnox is mainly network access.
I have predominantly used Portnox as a NAC solution for centralized, cloud-managed access control across our globally distributed data centers and offices, with more emphasis on offices than data centers. I integrated it with Microsoft Entra ID, on-premises LDAP servers, and JumpCloud to consume identities. I configured vendor-specific attributes, network access devices including Cisco, Ubiquiti UniFi Wi-Fi, and Aruba access points, and set up 802.1X authentication, access policies, and segmentation policies. This is my primary use case. I have less experience using it for zero trust purposes, as we have always used other tools and did not want to rely on something hosted in the cloud.
My use case for Portnox is access control, specifically focused on access control.
My initial use case for Portnox was as an on-prem solution that we used for network access control. We implemented ISO 27001 around that period, and Portnox served as our network access control. It helped in locking our ports where unauthorized users or devices in the environment were blocked. It worked pretty efficiently for us. The last time I used Portnox was earlier this year because I just moved roles. Where I am now, I've recommended that Portnox be implemented, which is currently under review. We might contact the vendor for a PoC, but it's something that I know works and has helped me significantly in terms of network access control.
We use Portnox for our primary network access control in all our offices to protect against unauthorized devices on our network.
We use it for dynamic VLAN assignment and for NAC, so network access control, to manage any external devices or internal devices that connect to our network. It auto-assigns them to the correct groups or VLANs.
I work at an IT firm where a couple of our end customers either use the product or want to onboard it in their environment. As a process engineer, I have to take care of certain presentations and discuss the deployment process with our company's customers. Some of our company's customers who use Portnox CORE's on-premises version found it to not be suitable for their usage or use cases. Later on, my company started to push Portnox Clear over Portnox CORE. Portnox Clear is a cloud-based solution, so our company's customers need not worry about deployment and other related areas regarding the product. Based on my own experience, I always encourage people to opt for Portnox Clear so that they don't have to worry about deployment and installation areas. One of our company's customers has an electricity distribution business with a lot of branches across the country, because of which they need to deal with a lot of connected devices. For our company's customer who deals in the electricity distribution business, I monitor routers and access points across the country, ensuring that no unauthorized sources are connected to them while ensuring the configuration and features of the product are accurate and up to date.
Our aim is to ensure compliance, so we use this solution for network access control, where we define the threshold for endpoint compliance. This extends to the Wireless LAN, which ensures that whatever compliance structure has been defined is maintained. We have many users working remotely, so we use Portnox to provide a high level of assurance. I'm an information security officer and we are customers of Portnox.
I work with a distributor. We Portnox, and NAC solutions.