Limit of ten (10) simultaneous sessions.
Though there is no ‘per-seat’ user or device limit but instead a limitation upon the maximum number of devices that may be simultaneously connected.
Devices attempting to connect at this limit will not be allowed to connect until another device disconnects.
RADIUS accounting data is used to determine this so make sure you have it configured, see the troubleshooting section regarding home tier sessions for more information.
Restricted to
Standard_B1andStandard_B2instances up to and inclusive of two (2) vCPUs and 1GiB RAM.Restricted to Standard SSD disk type for the OS.
Ephemeral OS disks are supported.
High Availability (HA) is is not supported.
Limited to a single VM.
Proxying RADIUS is disabled.
Accelerated Networking is disabled.
Encryption at Host is disabled.
Trusted Launch is disabled.
Assigning governance related policies to instances is blocked.
TLS session resumption is disabled.
impacts considerably device reconnection times for 802.1X when using EAP-(T)TLS.
Though supported, it is not recommended you enable MFA as the connecting user will be prompted on every reconnection which depending on your wireless equipment may happen when roaming between access points.
EAP-(T)TLS only support RSA certificates, support for ECDSA certificates is disabled.
Larger authentication payloads leading to slower authentications as they require more round trips to transmit certificate material.
This limitation does not apply to RadSec connections where ECDSA is supported.
The ‘team’ tier allows for:
Unlimited simultaneous sessions.
Use of all
Standard_B1andStandard_B2instances with no vCPU or memory restrictions.High Availability (HA) is supported.
Allow running of two service VMs.
Proxying RADIUS (federation only) is supported.
Only RADIUS authentication (‘Access-Request’) packets are forwarded.
Suitable for use with eduroam®.
Accelerated Networking is used where available.
TLS session resumption is supported.
EAP-(T)TLS support for ECDSA certificates.
The ‘enterprise’ tier further allows for:
Use of any instance type.
Proxying RADIUS accounting (‘Accounting-Request’) packets are forwarded.
Suitable for use with OpenRoaming™
Suitable for SSO use with WatchGuard™ Firebox, Fortinet FortiOS, SonicWall and other similar appliances.
Encryption at Host is used where available.
Trusted Launch is used where available.
Assignment of governance related policies to instances
Integration with Microsoft Defender for Cloud
