Deploy phishing-resistant, identity certificates to your entire fleet without a single help desk ticket. The SecureW2 JoinNow platform integrates with Google IAM to automate enrollment and enforce real-time, identity-aware access eliminating shared secrets and manual provisioning.
Overview
The SecureW2 JoinNow platform transforms Google Workspace into the authoritative identity source for your entire network, replacing vulnerable passwords with phishing-resistant digital certificates. By integrating directly with Google IAM, the platform automates the delivery of phishing-resistant identities and leverages Cloud RADIUS to perform live directory lookups on every connection attempt.
This ensures that network access is always identity-aware; if a user is suspended or moved to a restricted OU within the Google Admin Console, their access is revoked in real-time, providing total control over managed and BYOD fleets without manual IT intervention.
For BYOD and non-Chrome-managed devices, users enroll through the JoinNow portal using Google SAML SSO. Google authenticates the user and returns a signed assertion; JoinNow validates it, queries the Google directory, and delivers a certificate with a complete 802.1X configuration profile, no MDM required.
The platform integrates with Google IAM to perform identity lookups during RADIUS authentication. This ensures every network connection is verified against the most current data in the Google directory.
Organizations use Google Workspace identity to provide encrypted guest Wi-Fi. Guests authenticate using their Gmail IDs to gain secure, temporary access to the network without IT managing guest credentials.
SecureW2 integrates with Google Workspace to issue short-lived guest certificates scoped to a restricted VLAN. When a guest authenticates through JoinNow using their Gmail account, the Policy Engine validates their identity against Google’s OAuth endpoint and issues a time-limited certificate. Cloud RADIUS enforces the guest access policy, placing the device in the guest VLAN and blocking access to internal resources.
When the certificate expires, the guest’s access ends automatically, eliminating the need for manual credential revocation, shared Wi-Fi passwords, or IT helpdesk involvement.
Google Workspace OU and group memberships drive VLAN assignment at authentication time through Cloud RADIUS. Devices are placed in the correct network segment based on their current Google identity state. Active users in the Corporate OU have full access, active users in the Contractors OU have internet-only access, and suspended users or users not found in the directory are denied access.
VLAN assignment is evaluated at every authentication, so changes in Google Workspace OU or group membership take effect at the next connection attempt. A user moved to a restricted OU in Google Admin Console will receive restricted network access upon reauthentication, without certificate reissuance or profile update.
Frequently Asked Questions
Connect with our integration specialists to implement this solution in your environment and transform your security posture.