Who Authenticated Versus What the Network Carried
Access control knows who it let in. Flow data knows what actually moved. The interesting part is the difference between the two lists.
Your access control platform produces a clean report. Here is every device that authenticated, when, and as whom. It is accurate, and it is incomplete in a specific way: it can only tell you about devices it saw.
Your flow records produce a different list. Here is every endpoint that actually moved traffic through the network in the same window.
Both are correct. Neither is the answer. The answer is in the subtraction.
A device that carried traffic but never appears in the authentication log did not fail policy. It was never asked. That is the case worth finding, and it is structurally invisible to the tool that would normally find it, because a platform can only report on events that reached it.
This is why the two views sit on the same page rather than in two products. It is not a dashboard preference. Correlating them after the fact means exporting from both, aligning timestamps, normalising identifiers that each vendor formats differently, and doing it again next month. Teams start with good intentions and stop after the second export.
Worth saying plainly: a row in that difference is not proof of anything. Devices legitimately bypass authentication. Printers on a static VLAN, infrastructure with a MAC exception, a segment that was never in scope. Every finding of ours carries the sentence that says so, because a list of names without that sentence is how good people end up accused of things they did not do.
nac
correlation