NAC on a campus network: what actually breaks first
Network Access Control sounds simple until it meets a real device inventory. Here's what tends to surface first when rolling it out on a campus network.
Network Access Control (NAC) checks a device's identity and posture before granting it network access. On paper, this is straightforward: authenticate via 802.1X, place the device in the right VLAN, done. On a real campus network, the first thing that surfaces is usually the device inventory itself.
Campus networks accumulate a wide range of devices that can't do 802.1X cleanly — older lab equipment, certain IoT devices, printers, and specialist research hardware. A NAC rollout that assumes everything supports modern authentication will either lock these devices out or get bypassed entirely by frustrated staff plugging into unmanaged ports.
The practical sequence that avoids this: run NAC in monitor-only mode first, for long enough to see what's actually connecting and how. That discovery phase reveals the device population you're actually working with, not the one you assumed. Devices that can't do 802.1X get a deliberate fallback path — MAC authentication bypass into a restricted VLAN, not silent exclusion from network diagrams.
Only after that picture is clear does enforcement roll out, in stages, starting with segments where the device population is best understood — typically staff and administrative networks before labs and guest Wi-Fi.