# Setup LDAP Profile on Client Devices

{% hint style="success" %}
By following these steps, you can configure the **LDAP profile** on client devices to ensure proper authentication with the Entra ID (Azure AD) LDAP Server.
{% endhint %}

To allow client devices to authenticate with the Entra ID (Azure AD) LDAP Server, some devices, such as Android phones, require the installation of the **Client’s Authentication (CA) Certificate** (**`ca.pem`**). This certificate is needed for secure communication between the Access Point and client devices and can be exported via the EnGenius Cloud GUI.

<div align="left"><figure><img src="https://1886313717-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fus0DBFfmoooUbiDkYdbq%2Fuploads%2FygE90LcuSZa1k9H5AvB2%2Fimage.png?alt=media&#x26;token=56ff60cb-a496-4a06-82c7-415e6c81c3bb" alt="" width="563"><figcaption><p>Export CA Certificate</p></figcaption></figure></div>

### **To get started:**

1. Client devices scan for the **EnGenius WiFi SSID** and connect to it.
2. The **802.1X page** pops up and requests the Username and Password. (e.g., **`account@example.edu`**).
3. If the Certificate page pops up, click **Trust**.
4. For Android phones, it is required to specify the EAP method and Phase 2 authentication. Please refer to the following settings:

   * **EAP method:** Select **EAP-TTLS**.
   * **Phase 2 authentication:** Select **PAP**.&#x20;
     * <mark style="background-color:yellow;">(Note: If PAP is not supported on client devices, GTC is an alternative option but may have compatibility issues on specific devices, e.g., Chromebook.)</mark>
   * **Domain (Optional):** Enter the corresponding domain shown on Cloud GUI, e.g., **`engenius.ai`** (by default)

   <div align="left"><figure><img src="https://1886313717-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fus0DBFfmoooUbiDkYdbq%2Fuploads%2FVLC0639U4vBmvVTA3AR3%2Fimage.png?alt=media&#x26;token=7458da5b-e717-43c9-9ba3-fd2bed2052a6" alt="" width="563"><figcaption><p>Enter the Corresponding Domain Shown on Cloud GUI</p></figcaption></figure></div>

   * **Online Certificate Status:** Choose **Do not validate**.&#x20;
     * <mark style="background-color:yellow;">(Note: For Google Nexus devices, this option is not available. The certificate (</mark><mark style="background-color:yellow;">**`ca.pem`**</mark><mark style="background-color:yellow;">) must be installed.)</mark>

<div align="left"><figure><img src="https://1886313717-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fus0DBFfmoooUbiDkYdbq%2Fuploads%2F5WTYzxdeO1UVcwS96rWJ%2Fimage.png?alt=media&#x26;token=4bfd9a2d-ba8a-45b0-9d60-a3a4ecd1aef5" alt="" width="313"><figcaption><p>Example of Configuration for Android</p></figcaption></figure></div>
