Different Authentication Flows in 24Online for Educational Institutions
24Online is a comprehensive internet access management and captive portal platform widely used by schools, colleges, and universities. It provides centralized AAA (Authentication, Authorization, Accounting) via an inbuilt RADIUS server, branded captive portals, bandwidth policies, web filtering, session logging, and multi-site management.
For educational campuses, it supports high concurrent device loads (examples include deployments exceeding 26,000 Concurrent devices) and integrates with existing identity systems. Multiple authentication flows can be configured simultaneously and managed centrally, allowing different user groups (students, faculty, staff, guests) to use the method that best fits their needs while enabling role-based policies, dynamic VLAN assignment, and fair-usage controls.
1. Directory-Based Authentication (AD/LDAP / Microsoft Entra ID / SSO)
This is the primary and most seamless flow for enrolled students, faculty, and staff.
- Users connect to the campus Wi-Fi (or wired network) and are redirected to the branded captive portal.
- They enter their existing institutional credentials (Active Directory, LDAP, or Microsoft Entra ID / Azure AD).
- 24Online validates against the directory, applies group-based policies (e.g., different bandwidth packages or access rights for students vs. professors vs. senior management), and can assign dynamic VLANs.
- Supports Single Sign-On (SSO) so users log in once and can roam between wired and wireless networks without re-authentication.
- Benefits: No new accounts needed, automatic user lifecycle management (onboarding/offboarding), hierarchical concurrency limits, and reduced IT overhead.
2. Username and Password Authentication
- Users enter credentials stored in 24Online’s internal database (or linked systems).
- Common for temporary accounts, prepaid/postpaid packages, or when directory integration is not used.
- Supports PAP/CHAP protocols via the built-in RADIUS server.
- Can be combined with MAC/IP binding or re-authorization for added control.
3. OTP-Based Authentication (SMS / Email)
- User enters a mobile number or email on the captive portal.
- Our product, 24Online generates and sends a one-time password via integrated SMS gateways (20+ supported) or email.
- User enters the OTP to gain access (often time-limited).
- Frequently used for guests, visitors, or as a second factor (MFA).
- Supports alerts for registration, login, logout, payment reminders, etc.
4. Voucher / Coupon / PIN Authentication
- Administrators or kiosks generate printable or digital vouchers/coupons with unique usernames/passwords or PINs, often with expiry, data limits, or time limits.
- Users redeem the voucher on the captive portal.
- Ideal for cafeteria visitors, event attendees, short-term guests, or walk-in library users.
- Supports online purchase, branding/custom templates, and pin-aging (expiry).
5. QR Code Authentication
- Users scan a QR code displayed on the captive portal, printed materials, or digital screens.
- The QR links to a pre-configured access package or generates temporary credentials.
- Useful for quick guest access, libraries, or high-traffic areas without typing credentials.
6. Social Media / Self-Registration Authentication
- Users authenticate via social media accounts (e.g., Facebook, Google, or other supported providers) or complete a self-registration form on the captive portal.
- Often includes acceptance of terms of use and optional demographic data collection.
- Suitable for temporary or guest users; can be combined with approval workflows.
7. MAC / Device-Based / Recognized Device Authentication
- Devices are pre-registered or recognized by MAC address.
- Once authenticated, the device can reconnect automatically (with optional time or policy limits).
- Supports “save my device” options and is useful for personal devices in BYOD environments.
- Can work alongside other methods for seamless re-access.
8. Approval-Based / Sponsored Access
- A user requests access (via portal form or self-registration).
- An authorized person (faculty, admin, or sponsor) approves the request.
- Common for guest lecturers, temporary researchers, or external visitors requiring oversight.
9. Certificate-Based / 802.1X Authentication
- Stronger security option using digital certificates for device or user authentication.
- Often paired with RADIUS and 802.1X for enterprise-grade Wi-Fi security.
- Helps eliminate password sharing and is particularly useful in BYOD campus environments.
- Supports integration with existing PKI infrastructure.
10. Multi-Factor Authentication (MFA) Combinations
- Any primary method (directory credentials, username/password, etc.) can be layered with a second factor such as OTP (SMS/email), authenticator apps, or tokens.
- Enhances protection for sensitive academic data and helps meet security/compliance needs.
Additional Supporting Capabilities
- Role-based and group-based policies – Different packages, bandwidth limits, web-filtering rules, and VLANs based on user type or AD group.
- Location-based captive portals – Different login pages or methods depending on campus area (library, hostel, classroom, etc.).
- Seamless roaming – Login-once across wired and wireless.
- Guest and temporary access – QR, vouchers, OTP, or social login with strict time/data limits.
- Reporting and visibility – Full session logs, usage reports, and audit trails for compliance.
These flows allow educational institutions to balance security, user convenience, and administrative control. Directory/SSO integration is typically preferred for permanent users, while OTP, vouchers, QR codes, and social/self-registration handle guests and temporary needs. Multiple flows can run in parallel on the same platform and be centrally managed.
Consult our experts for a customised hospitality internet solution tailored to your property.