Disclaimer: I had to blur out the other Wi-fi networks in this video. I want to keep some sense of privacy for myself and the surrounding areas. You may have small parts of this video that are mostly blur. I will revisit this when I can go to a location with no existing Wi-Fi.
I setup an Engenius EAP1200H to use WPA2 enterprise wireless security. This will allow each user to have their own username and password to access Wifi in lieu of a shared password. This method is recommended for any business that has 10 or more employees. This is more secure than using a shared password as user accounts can be shut off with minimal interruptions to your business. I used Active Directory and Network Policy Server for my authentication. It wasn't perfect, but it did get done. The process is largely the same for any Engenius access point. The procedure for Active Directory and RADIUS should be the same across the board. This procedure may work for other brands of access points.
What I used:
(2) Server 2019 Standard servers: 1 for AD, 1 for RADIUS
(1) Engenius Access Point
(1) POE switch