Mosyle transforms device identity data into dynamic network policies that adapt to device trust in real time. Replace shared Wi-Fi passwords with phishing-resistant certificates automatically deployed through Mosyle. Every device on campus or in the office authenticates with its own credential.
Overview
SecureW2 integrates with Mosyle to deliver automated certificate enrollment for Apple device fleets, replacing shared Wi-Fi passwords and PSKs with unique, phishing-resistant certificates issued through Mosyle configuration profiles. In K-12 schools and higher education, this eliminates the single biggest network security gap: the shared password posted on the classroom whiteboard. Each iPad and Mac receives its own certificate during MDM enrollment, and Mosyle distributes it without any user interaction required.
ACME, the preferred enrollment path for supported Apple devices, combines the standard ACME protocol with Apple hardware attestation to verify device authenticity before any certificate is issued. For older devices or non-ACME environments, Dynamic SCEP generates a unique per-device challenge at enrollment, eliminating the static shared secret used in traditional SCEP. JoinNow Cloud RADIUS enforces access policy at authentication by reading the live Mosyle device state to assign VLANs, segment student and staff traffic, and automatically revoke access when a device leaves management.
For devices that do not support ACME, Mosyle delivers an SCEP profile with a unique per-device challenge. JoinNow CloudConnector generates the challenge after verifying the device’s managed status in Mosyle, eliminating the static shared secret used in traditional SCEP.
For devices that do not support ACME, Mosyle delivers an SCEP profile with a unique per-device challenge. JoinNow CloudConnector generates the challenge after verifying the device’s managed status in Mosyle, eliminating the static shared secret used in traditional SCEP.
ACME is the preferred enrollment protocol for Apple devices because it integrates with Apple's hardware attestation mechanism. When a device initiates ACME enrollment, it contacts Apple's attestation server, which returns a signed attestation statement that includes the device's serial number, hardware model, confirmation that the OS has not been tampered with, and proof that the certificate's private key is bound to the device's Secure Enclave, a dedicated coprocessor whose keys cannot be exported or copied.
SecureW2's ACME API Gateway validates Apple's cryptographic signature, and then the JoinNow Policy Engine queries the Mosyle Identity Lookup Provider to confirm that the device is actively managed in Mosyle. A device that passes hardware attestation but is not found in Mosyle does not receive a certificate. ACME enrollment is supported on macOS, iOS 16+, and iPadOS 16+, and Mosyle distributes the profile through standard configuration profile deployment.
Once enrolled, the device stores a certificate in its Secure Enclave that cannot be extracted, copied, or shared. If a device leaves Mosyle management, SecureW2 detects the change during the next revocation evaluation and automatically revokes the certificate. The device fails EAP-TLS on the next connection attempt.
Mosyle Manager's Shared iPad mode lets multiple students use a single physical iPad, each signing in with their Managed Apple ID for a separate home screen session. This means certificates must be scoped to match how access policy is enforced. Device-scoped certificates are the default and preferred configuration for network authentication in most Shared iPad deployments.
The certificate is issued to the device during MDM enrollment and remains on it regardless of which student is logged in, allowing the iPad to connect to school Wi-Fi without each student authenticating individually. User-scoped certificates are installed per user session and removed at logout; they enforce per-student network policy but require the enrollment flow to run at each login, adding latency at sign-in.
The recommended K-12 approach uses device-scoped certificates issued via the Mosyle device enrollment profile, with the JoinNow certificate template encoding device identity attributes, such as the device serial number and device client ID, rather than user attributes like UPN or email. Per-student network segmentation, for example, different grade levels on different VLANs, is handled at the RADIUS layer, where Cloud RADIUS reads group attributes at authentication time and applies policy accordingly, without requiring separate certificates per student.
Frequently Asked Questions
Mosyle Manager is designed for K-12 schools and educational institutions and includes features specific to those environments, such as Shared iPad support, Apple School Manager integration, classroom management, and education-focused app management. Mosyle Business is aimed at corporate Mac and iOS fleets and focuses on device management, security policy enforcement, and enterprise app deployment. The SecureW2 SCEP and ACME certificate enrollment integration works with both products. Both support SCEP profile deployment and ACME profile payloads via standard Apple MDM mechanisms. The primary configuration difference is how you scope the certificate template; education deployments often use device-scoped certificates for Shared iPad, while Mosyle Business deployments typically use user-scoped or device-scoped certificates based on the organization's policy requirements.
Connect with our integration specialists to implement this solution in your environment and transform your security posture.