The Group Policies functionality (formerly known as User Groups) allows administrators to manage and control Wi-Fi access by defining access policies and rules to automatically assign them to users. This feature enhances network organization, security, and simplifies network access management.
Note: Organizing users into different custom groups is an enterprise feature available in the Enterprise Edition. If you are using a standard license, a restriction prompt will appear when attempting to add a new group policy.
Group Policy Setup
Each Group Policy comes with several configurable attributes:
Name: The Group Policy Name is a label you define for each group policy. This name will appear in the user profile and the user table list, making it easy to identify and organize group policies. The Group Policy Name serves as a reference for administrators to quickly recognize and distinguish between different group policies. The name of the default group policy can never be changed.
Access Permission: Defines if the policy blocks or allows access to the network (Allow Access or Deny Access). If set to deny access, users sorted into this group will receive a "You're not authorized" notification on the Splash Page upon connection.
Time Restriction Policy: Defines whether the policy enforces restricted session time limitations or not (Unlimited). If the session time is restricted, the interface displays the Internet Plan subsection, where the administrator can choose among 3 options:
Assign a specific Internet Plan: This option allows you to select a specific internet plan from the list of available options.
Inherit Location Default Internet Plan: This option automatically assigns the default internet plan of the location where the user signed up. In this way, you can customize the internet plan for members of the same group depending on the location where they signed up.
Require users to obtain a plan (PIN code or plain plans): It does not assign any specific restriction upfront but allows to define that users need a time allowance in order to get authorized. In this case, users need to be provided with an internet plan in a different way to access the network. This option is useful, for example, if you want to offer Wi-Fi access with a pay-per-use model or controlled distribution.
Sponsor Validation Exception: User accounts managed via the Sponsor Validation workflow represent a native exception to these time restrictions. They do not follow the Unlimited, Restricted, or Deny settings of the group because their access is governed entirely by the validity timestamp granted by their host. They remain online with full internet privileges until that specific expiration timestamp is reached.
For the first two Time Restriction options (Assign a Specific Internet Plan and Inherit from Location), you can also set the Force plan if mismatch on next login option.
If Force plan if mismatch on next login is enabled: Any modification to the internet plan configuration in the group will take effect the next time the user logs in. The user will be forced to use the new internet plan settings, replacing any previous plan with the new one.
If Force plan if mismatch on next login is disabled: Changes to the internet plan will only impact new users assigned to the group. Existing members will continue using their current plan and will not have their plan updated during subsequent logins.
Important Configuration Alert: If you are changing a policy from "Unlimited" to "Restricted", you must select "Force plan if mismatch on next login". Without this option enabled, existing users will be switched to a Restricted status but will not have any internet plan assigned to their profile, preventing them from browsing at all upon their next login. Enabling this option ensures they automatically receive the new internet plan settings on login.
Access Control Settings: Access control settings allow you to limit device registration and simultaneous connections for members of each user group.
Limit the maximum number of devices allowed per user: Defines the total absolute number of unique devices a user can register under their profile.
Limit Maximum Concurrent Connections: This setting defines the maximum number of concurrent sessions a user from the group can have at the same time. For example, if you set this limit to "3", each user in that group will only be able to maintain 3 active connections to the Wi-Fi network at any given time. A fourth simultaneous attempt will trigger a "User already connected" notification.
Radius Service Attributes: Radius attributes are used for managing user access to the network. These attributes depend on the vendor's supported features and need to be properly configured on the vendor's side. These parameters can be defined the same for all locations, or you can choose to differentiate them depending on the location where the member is logged in. Examples of Radius service attributes include:
VLAN
Filter ID
QoS (Quality of Service) - Up/Down limits
Group Policy Deletion and Restrictions
Deleting a Group Policy: If a group policy is deleted, all associated rules in the Guest and Trusted tabs are also deleted.
Assigned Group Policies: A group policy that is currently assigned to users cannot be deleted. The "Delete" action in the dropdown menu will be automatically disabled (greyed out) until all members are reassigned to a different policy.
Default Group Policy: The default user group can never be deleted.
Group Policy Assignment
All users in the Cloud4Wi account, including Guest and Trusted Users, always have a Group Policy assigned that defines the authorization rules to access the network.
Users are assigned to a group policy based on a prioritized Drag-and-Drop Hierarchy inside the dashboard. Rules are evaluated from the top row downward, and the first matching rule determines the policy assignment. There are different sets of Rules depending on the type of user:
Guest Access Rules: An ordered set of rules that define which policy to assign to Guest Users (e.g., users signing up from the captive portal). These rules are evaluated when guests register through any guest onboarding channel.
Trusted Access Rules (Microsoft Entra ID Integration): An ordered set of rules that define which group policy to automatically assign to Trusted Users (e.g., users authenticating with a corporate IdP like Microsoft Entra ID). These rules are evaluated when a Trusted User is added to the directory and are re-evaluated automatically via a daily sync.
Automated Sync: If a user's role changes within Microsoft Entra ID, the daily synchronization automatically updates their Cloud4Wi access permissions based on their new Entra ID Group.
Secure by Default: All newly initialized Entra ID users are automatically assigned to a default fallback policy with blocked network access until an explicit rule authorizes them.
Default Group Policy: Upon account setup, a default group policy is created. Unless a rule specifically assigns a user to a different Group Policy, users are assigned to the Default Group Policy.
Legacy Users: Users who registered before the Group Policy capability was available are automatically assigned to the default group policy to ensure continuous connectivity.