Agentless NAC
Evaluation Kit

See what is connected. Prove what you can control.

Plan a focused, standalone EasyNAC proof of concept with practical tests, a deployment checklist and an editable scorecard. Use your devices, your policies and evidence from your network.

Free resources. No email required.

Cover of the EasyNAC Agentless NAC Evaluation Kit guide
A practical, 11-page proof-of-concept guide
10 practical testsVisibility, trust, protection and access
17 readiness checksScope, topology, policy and preparation
1 editable workbookRecord results and agree your next step

A clear path through your pilot

Turn requirements into measurable results.

Start with a representative part of your network. Agree what success looks like, run the relevant tests and record what actually happens.

01

Plan your pilot

Choose the devices and traffic paths for your standalone pilot. Check dependencies and agree a rollback procedure.

02

Run the tests

Observe first, then test approved access policies. Verify real traffic as well as the information in the console.

03

Review the evidence

Capture results in the scorecard. Identify gaps, assign follow-up actions and decide whether to expand or retest.

Inside the kit

Ten tests for an agentless NAC evaluation.

Open a test to see the approach and evidence to capture. Select the tests that match your scope. AD, security integrations, BYOD and guest workflows are optional where they do not apply; record the reason in the scorecard.

01Agentless network visibilityCan you see managed and unmanaged devices?

Set up. Choose known laptops, phones, printers and IoT devices on the pilot LAN and Wi-Fi. Keep a reference inventory.

  1. Connect the sample without installing a NAC agent on the endpoints.
  2. Compare discovered MAC/IP addresses, hostnames and available device details with the reference list.
  3. Reconnect a test device and check the updated inventory. Resolve missing or duplicate records.
What to record

Found / expected devices; discovery interval; wired and Wi-Fi coverage; missing records.

Agree success before testing. The agreed device sample is visible within the agreed interval, without endpoint NAC agents.

02Active Directory Auto TrustCan domain membership drive device trust?

Set up. Connect a supported AD integration. Use one valid domain computer and one designated non-domain test device.

  1. Check the AD match and Auto Trust result for the domain computer.
  2. Connect the non-domain device and verify it does not receive domain-based trust.
  3. Check access for both devices against the agreed domain and unknown-device policies.
What to record

Domain match; trust status; policy; allowed and restricted destinations.

Agree success before testing. Valid AD computers receive the agreed trust policy; the non-domain device follows its separate access policy.

03Agentless security complianceCan existing security tools inform access?

Set up. Select a supported AV, EDR or endpoint-management integration and the posture fields it actually supplies.

  1. Record a compliant device and its source status, such as AV health or patch status where available.
  2. Use an approved test noncompliance condition and check the resulting access or remediation policy.
  3. Restore compliance, refresh the integration and verify the intended access returns.
What to record

Integration and fields used; data age; policy change; restriction and restoration results.

Agree success before testing. The selected compliance signal drives the agreed restriction and restoration within the agreed interval.

04Device profiling & MAC-spoofing protectionCan trust go beyond an allow-listed MAC address?

Set up. Profile known device types. Reserve two isolated lab endpoints and test identities for the spoofing check.

  1. Compare device type, OS and hostname where available; apply the agreed profile or custom tag.
  2. With the original lab endpoint disconnected, reuse its test MAC on the second lab endpoint.
  3. Check the fingerprint mismatch, trust decision and configured response; restore the test identity.
What to record

Profile accuracy; fingerprint attributes; spoofing event; trust and access outcome.

Agree success before testing. The agreed profiles are usable, and the simulated impersonator does not inherit trusted access.

05Rogue-device detection & restrictionCan you restrict an unknown device on its VLAN?

Set up. Trust the approved pilot devices. Define allowed, blocked and remediation destinations for one unknown test device.

  1. Connect the unknown device and record detection, alert and assigned access policy.
  2. Test its allowed and blocked destinations on the existing VLAN, without moving it to a quarantine VLAN.
  3. Check an approved peer remains connected, then approve or release the test device and verify access.
What to record

Detection-to-restriction interval; same-VLAN results; remediation access; approved peer connectivity.

Agree success before testing. The unknown device is restricted as agreed while the approved peer retains access on the existing network.

06Lateral-spread protectionCan suspicious scanning trigger protection?

Set up. Enable the agreed detection policy. Use a designated lab source and reserved test targets; use no actual malware.

  1. Run a bounded, benign scan using the agreed lab procedure and targets.
  2. Check the detected activity, source device and configured alert or restriction.
  3. Verify the source access result and an unaffected peer, then release the test device and restore access.
What to record

Detection event; source identity; response interval; restriction and release results.

Agree success before testing. The agreed scan is detected and triggers the configured response against the correct test device.

07Controlled BYOD registrationCan staff register devices within your rules?

Set up. Prepare the BYOD portal, permitted user groups and device rules. Use test users and personal test devices.

  1. Register a device as an eligible user and check the owner association and assigned policy.
  2. Check permitted and restricted destinations from the registered device.
  3. Test an excluded user or device and, if configured, the per-user device limit. Revoke the test registration.
What to record

Registration steps; owner mapping; user/device limits; access and revocation results.

Agree success before testing. Eligible BYOD devices receive the agreed access; excluded registrations and configured limits are enforced.

08Guest & consultant accessCan visitors get only the access they need?

Set up. Prepare a guest template or consultant role, a test sponsor, permitted resources and an access expiry time.

  1. Pre-register or approve the visitor through the selected sponsor workflow.
  2. Connect the visitor device and check its limited-access policy against allowed and blocked destinations.
  3. Confirm access expires or is revoked as configured, and retain the sponsor and visitor records.
What to record

Sponsor steps; guest identity; resource restrictions; expiry and revocation outcomes.

Agree success before testing. The approved visitor receives only the agreed access, which ends at expiry or revocation.

09Automated threat responseCan a security alert trigger network restriction?

Set up. Configure a supported security alert source and response rule. Use a benign event identifying a designated lab endpoint.

  1. Send the test alert through the agreed integration or monitored alert mailbox.
  2. Check the endpoint match, response rule and actual restriction; confirm an approved peer remains connected.
  3. Review the event trail and optional SIEM/syslog output, then authorize release and verify access returns.
What to record

Event-to-restriction interval; matching attributes; peer connectivity; release result.

Agree success before testing. The alert restricts the correct endpoint as agreed, with an event trail and a verified release procedure.

10Deception & hacking detectionCan a decoy expose suspicious activity?

Set up. Enable deception and identify the lab decoy/service and test source with the EasyNAC engineer.

  1. Make a harmless connection or dummy login attempt to the designated decoy service.
  2. Review the detection, source device and configured alert or response policy.
  3. Check the recorded outcome and any configured restriction, then clear the test condition and restore access.
What to record

Decoy interaction; detection time; source match; alert or restriction; cleanup result.

Agree success before testing. The agreed decoy interaction is detected, attributed to the correct source and handled by the configured policy.

Start in observation mode. Run enforcement, bounded scan and decoy tests only on your approved pilot devices, with a release procedure and management access in place.

Download and make it yours

Your evaluation starts here.

Use the guide and workbook together. Adapt the scope and acceptance criteria to your organization.

PDF · 11 PAGES

Evaluation guide

A practical walkthrough from planning to the final evaluation decision.

  • Illustrative deployment architecture
  • Setup, steps and evidence for all ten tests
  • Measures for coverage, response and operating effort
  • A structure for your management summary
Download evaluation guide
XLSX · 4 WORKSHEETS

Customer value workbook

Connect EasyNAC features to the benefits you verify in your own network.

  • Customer priorities, verified benefits and open gaps
  • 10 core demonstrations plus an optional branch sensor check
  • Actual infrastructure changes and time saved
  • Simple result-based scorecard and 17 readiness checks
Download editable workbook

Before you begin

A few practical questions.

Does this include EasyNAC software?

The kit contains planning and evaluation resources. To arrange access to EasyNAC software or appliances for a pilot, contact our team. We will confirm the scope, licensing, sizing and deployment requirements with you.

Do I need a NAC agent on every device?

This kit focuses on an agentless evaluation. Include a representative mix of managed and unmanaged devices. Detailed security posture may depend on supported integrations or credentials; confirm the evidence available for each device type.

What should we check about our network?

Confirm appliance placement, the protected VLANs and required addresses for your LAN and Wi-Fi. A SPAN/mirror port is not required. Add Enforcer Sensors only if branch coverage is part of your pilot. This kit focuses on a standalone appliance and does not include authentication-system tests.

How long should the evaluation take?

Set a schedule around your scope, integrations, approvals and test windows. Agree the acceptance criteria and review date before starting. The guide helps structure the work without assuming the same deployment time for every network.

Build a pilot around your network.

Bring a simple site map, your main device groups and the access problem you want to solve. We’ll help you discuss a suitable EasyNAC evaluation.

Request an evaluation

Choose which optional services EasyNAC may use. You can change your choice at any time using Cookie preferences in the footer.

Your choice is remembered for 180 days in this browser. Read our Privacy Policy.