Configure EAP-TTLS/PAP on Android Devices for RADIUS

EAP-TTLS/PAP is a widely deployed authentication protocol that provides enhanced network security through digital authentication, ensuring that the appropriate users and devices have access to JumpCloud RADIUS. Learn to configure EAP-TTLS/PAP for your JumpCloud RADIUS clients that run Android. 

Important:
  • The two use cases that require EAP-TTLS/PAP in JumpCloud are:
    • Delegated Auth with Entra ID. See Authenticate to RADIUS with Entra ID.
    • 6-digit time-based one-time password (TOTP) multi-factor authentication (MFA) for RADIUS-based VPN authentication. 
  • We do not recommend using PAP without EAP-TTLS or your configuration will be insecure.
  • If you are not using one of these two use cases then JumpCloud recommends using PEAPv0 (also referred to as EAP-PEAP or PEAP-MSCHAPv2) for authentication because it requires no additional configuration as this is the default used by all Operating Systems.

Prerequisites:

Configuring a WiFi Profile on Android Devices

Note:

These steps may vary slightly depending on the make and model of your Android device.

To configure a WiFi profile with EAP-TTLS/PAP on Android devices:

  1. On an Android device, go to Settings > Network & internet and tap on Internet.
  2. Either select the WiFi SSID from the list, or select + Add network and create a new wireless profile.
  3. (Optional) Enter the Network SSID.
  4. Configure the following settings:
    1. EAP method: TTLS.
    2. Phase 2 authentication: PAP.
    3. CA certificate: Trust on First Use.
    4. Identity: Enter the user’s JumpCloud email address (or Entra ID username if using delegated authentication).
    5. Password: Enter the user’s JumpCloud password (or Entra ID password if using delegated authentication).
    6. Tap Save.
  5. Tap Connect.
  6. When prompted for Is this network trusted? Tap Yes, connect.
Back to Top

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case