Glossary

MAC Authentication Bypass (MAB)

MAC Authentication Bypass (MAB) is a network access method that authenticates a device by its MAC address when the device cannot run 802.1X. The switch or access point sends the MAC address to a RADIUS server, which checks it against an allowed list and grants or denies access.
Last updated: August 10, 2026

What MAB is

MAC Authentication Bypass (MAB) is a fallback authentication method for devices that cannot speak 802.1X. Instead of a username, password or certificate, the network identifies the device by its MAC address — the hardware identifier burned into its network interface.
MAB exists because real networks are full of devices with no way to log in: printers, IP cameras, badge readers, sensors, medical equipment and most of the IoT. These devices still need controlled access, and MAB is the mechanism that provides it.

How MAB works

When a non-802.1X device connects to a switch port or wireless SSID, 802.1X authentication is attempted first and times out because the device has no supplicant. The network then falls back to MAB.
The authenticator learns the device's MAC address and sends a RADIUS Access-Request that uses the MAC address as both the identity and, in many implementations, the password. The RADIUS server checks that MAC against a known-device list or an endpoint database and returns Access-Accept or Access-Reject.
On accept, the server can return policy attributes — a VLAN assignment, a downloadable ACL or a role. The device is then placed in the right segment and can only reach what it needs.

MAB and 802.1X working together

MAB is almost never deployed alone. The standard pattern is to configure a port or SSID to try 802.1X first and fall back to MAB only when no supplicant responds. That way, capable devices get strong authentication automatically, while headless devices still get on through MAB.
This ordering matters: putting 802.1X first means a device that can authenticate properly always will, and MAB only ever handles the devices that genuinely cannot.

MAB and device profiling

A bare MAC address says little about what a device actually is. That is why modern deployments pair MAB with device profiling. It inspects signals such as DHCP fingerprints, HTTP user-agent strings and traffic patterns to classify the device — say, as a particular model of printer or IP camera.
Profiling lets the network apply policy by device type and flag anomalies — for example, a MAC that claims to be a printer but behaves like a laptop.

Security limits of MAB

MAB is convenient but weak as a standalone control. A MAC address is not a secret. It is printed on device labels and broadcast over the air, so an attacker can read one and spoof it to impersonate an allowed device. Relying on MAB alone is therefore risky.
To reduce the exposure, treat MAB as one layer among several rather than a complete answer.

  • Combine MAB with device profiling so a spoofed MAC on the wrong device type is flagged.
  • Confine MAB devices to tightly scoped VLANs or ACLs that limit what they can reach.
  • Monitor for the same MAC appearing in two places or moving unexpectedly.
  • Move any device that can support it to 802.1X, ideally with EAP-TLS certificates.

MAB and MAC randomization

A complication for MAB is that modern phones and laptops now randomize their MAC address per network for privacy. A randomized, changing MAC makes a fixed allow-list unreliable for those devices, which can break access or inflate the device count.
The practical answer is to keep MAB for headless IoT gear that uses a stable hardware MAC. User devices should move to 802.1X or per-device keys that do not depend on a static MAC at all.

MAB in cloud NAC

MAB is a core part of any network access control strategy because the IoT is not going away. The challenge is running it consistently across many sites without a RADIUS server in every closet.
Cloud4Wi's Cloud WiFi NAC delivers MAB together with automatic device fingerprinting and cloud RADIUS. Headless and IoT devices are identified, authorized and segmented from one console, and the same policy applies everywhere — whether the site has ten devices or ten thousand.

MAB compared with other access methods

It helps to place MAB next to the alternatives. 802.1X is stronger but needs a supplicant. Per-device keys such as PPSK, iPSK and MPSK give unique credentials without a supplicant. They are a better choice than MAB for devices that can store a key. A captive portal suits human guests rather than headless machines. MAB fills the specific gap of devices that can do none of these.
Seen this way, MAB is not a competitor to those methods but the floor beneath them. It is the option of last resort for a device whose only identity is a hardware address. A mature network uses 802.1X first, per-device keys where keys can be stored, a captive portal for guests, and MAB only for the headless devices that fit nowhere else. Each is confined to the segment its weakness deserves.
In short, the right question is never whether MAB is strong — it is not — but whether a given device has any better option. For the growing population of headless and IoT devices that do not, a carefully scoped MAB deployment is a reasonable and widely used answer. Watched by profiling and monitoring, it brings them under control rather than leaving them on an open or unmanaged network.

— FAQ

Frequently asked questions

Everything you need to know about MAC Authentication Bypass and how it works.

On its own, no. MAC addresses are printed on labels and broadcast over the air, so they are easy to read and spoof. MAB becomes acceptable when combined with device profiling, tight VLAN or ACL segmentation, and continuous monitoring, which together catch a spoofed address being used by the wrong type of device.

Use MAB only for devices that cannot run an 802.1X supplicant, such as printers, IP cameras, badge readers and most IoT sensors. Every device capable of 802.1X — especially laptops and phones — should authenticate with it, because 802.1X provides far stronger, identity-based security than a MAC address ever can.

The switch or access point first tries 802.1X, which times out for a device with no supplicant. It then learns the device's MAC address and sends it to a RADIUS server as the identity. The server checks the MAC against an allow-list and returns accept or reject, often with a VLAN or ACL to apply.

Profiling inspects signals like DHCP fingerprints, user-agent strings and traffic patterns to classify what a device truly is. Combined with MAB, it lets the network apply policy by device type and detect mismatches — for example a MAC registered as a printer that suddenly behaves like a laptop, which suggests spoofing and can be quarantined automatically.

It can. Many phones and laptops now randomize their MAC per network for privacy, which makes a fixed allow-list unreliable and can inflate device counts. The fix is to keep MAB for headless IoT gear with a stable hardware MAC, and move user devices to 802.1X or per-device keys that do not depend on a static MAC.

Ready to reimagine your WiFi?

Spin up your 30-day free trial in minutes, or book time with our team of WiFi experts to scope an enterprise rollout.

  • SOC 2 certified
  • No credit card required
  • GDPR & global compliance
  • No rip-and-replace