Certificate-Based Authentication for Rugged and Enterprise Device Fleets via SOTI MobiControl

SOTI transforms device identity data into dynamic network policies that adapt to device trust in real time. Issue phishing-resistant certificates to every managed device through SOTI MobiControl, including rugged handhelds, clinical tablets, and shared kiosk endpoints.

Overview

One Certificate Per Device. Zero Shared Passwords.

SecureW2 integrates with SOTI MobiControl to provide certificate-based Wi-Fi and network authentication for enterprise mobile fleets, including ruggedized handhelds, barcode scanners, mobile workstations, and Android devices in field service, retail, healthcare, and manufacturing. The integration links MobiControl device management to JoinNow Dynamic PKI and JoinNow Cloud RADIUS, replacing shared Wi-Fi passwords and static SCEP secrets with per-device x.509 certificates provisioned automatically via MobiControl profiles.

 

When a device enrolls in MobiControl, it receives an SCEP certificate profile that triggers automated enrollment with SecureW2. The Policy Engine validates the device against MobiControl before issuing credentials, and Cloud RADIUS performs a live lookup to MobiControl at every authentication event to reflect the device’s current enrollment state. This results in a fully cloud-native certificate authentication stack built for enterprise mobile operations, without on-premises PKI infrastructure or shared passwords.

Use Cases
Device vs User Certificates for Shared Endpoints
VLAN Segmentation by Device Type from MobiControl Groups
Video Overview

See the Integration in Action

Want to See More Demos, Click Here
How It Works

Automate Certificate Enrollment via SOTI MobiControl

Dynamic SCEP Enrollment via SOTI MobiControl

SOTI MobiControl delivers a SCEP certificate profile containing a unique per-device challenge to each managed endpoint. CloudConnector receives the SCEP request and sends a challenge webhook to MobiControl to validate the device identity before any credential is issued. Once validated, Dynamic PKI issues a device-bound certificate that is delivered to the device keychain automatically and used for 802.1X EAP-TLS network authentication.

Device-Certificate Authentication for Shared Endpoints

Shared and rugged devices authenticate using device certificates;  no user identity is required at the network edge. At each connection attempt, Cloud RADIUS performs a live query to SOTI MobiControl to verify the device record is still enrolled and active before returning a RADIUS decision. Devices removed from MobiControl receive a RADIUS Reject at the next authentication event, even if their certificate has not yet expired.

Use Cases

Deployment & Architecture Detail

Rugged Device Fleet Lifecycle Automation

Ruggedized devices in warehouses, fields, and retail environments are replaced, repaired, and redeployed more frequently than office endpoints. Each lifecycle event, device returned for repair, swapped for a replacement unit, or moved to a different MobiControl group, needs to be reflected in the network access layer without IT intervention. When a device is unenrolled from SOTI MobiControl, Cloud RADIUS detects the missing device record and denies access, even if the device still holds a valid certificate.

 

When a replacement unit is enrolled and assigned a SCEP profile by MobiControl, SecureW2 issues a fresh certificate automatically. The new device inherits the same network access as the unit it replaced, based on its MobiControl group membership, with no manual RADIUS configuration required. The replacement cycle is transparent to the network team.

 

For high-churn fleets where dozens of devices turn over each month, this model eliminates coordination overhead between MDM administrators and network engineers. Device lifecycle is managed in MobiControl; network access policy enforces itself at every authentication without human involvement.

VLAN Segmentation by Device Type from MobiControl Groups

Cloud RADIUS reads MobiControl device group membership at authentication time and maps group values to RADIUS policy attributes, including VLAN assignments. This supports network segmentation scenarios common in enterprise mobile operations, separating warehouse floor devices from office devices, isolating contractor-owned devices from corporate infrastructure, or placing devices under remediation into a restricted segment. A device in the "Warehouse Floor" group can receive a VLAN scoped to warehouse management systems only, while a device in "Contractor Devices" receives an internet-only VLAN, and a device not found in MobiControl receives a RADIUS Reject.

 

Because VLAN assignment is evaluated at every authentication event, changes in MobiControl group membership take effect at the next connection attempt. No static VLAN assignments are stored in the certificate, and no manual RADIUS policy updates are required when devices are reassigned between groups, transferred between locations, or decommissioned.

Frequently Asked Questions

Soti Integration — Common Questions

What device types and operating systems does the SOTI MobiControl integration support?

The integration supports all device types managed by SOTI MobiControl, including Android, Windows Mobile/CE, Windows 10 IoT, and iOS. This includes ruggedized devices from vendors such as Zebra, Honeywell, and Panasonic. Certificate enrollment via Dynamic SCEP is supported on all platforms where MobiControl can push certificate profiles. Cloud RADIUS authentication via EAP-TLS is supported on any device that presents the issued certificate over 802.1X.

What is the difference between Dynamic SCEP and traditional SCEP for rugged device fleets?

Traditional SCEP uses a single static shared secret embedded in the SCEP profile, used by every device in the fleet. For large ruggedized device fleets hundreds or thousands of devices across multiple locations a single compromised SCEP secret puts the entire fleet's certificate enrollment at risk. Dynamic SCEP generates a unique challenge per device per enrollment request, tied to that specific device's MobiControl identity. A compromised challenge is useless to an attacker because it is valid only for the device it was issued to and for a single use.

What happens when a device is unenrolled or wiped from SOTI MobiControl?

On the device's next authentication attempt, Cloud RADIUS queries MobiControl and finds the device is no longer enrolled. Cloud RADIUS returns a RADIUS Reject, and the network access point denies the connection. No manual certificate revocation is required. Because Cloud RADIUS performs a live MobiControl lookup at every authentication event, unenrollment events take effect at network access time without waiting for certificate expiry.

Can this integration support device-only authentication with no user identity on the device?

Yes. Many ruggedized devices in warehouse, retail, and field operations are shared-use or kiosk-mode devices without a persistent logged-in user identity. SecureW2 supports device-only certificate enrollment where the certificate SAN is populated exclusively with device attributes from MobiControl device ID, serial number, device group. Cloud RADIUS evaluates authentication based on device identity alone, without requiring a user UPN or email in the certificate. Device group membership in MobiControl drives VLAN and access policy for these deployments.

What MobiControl API permissions are required for this integration?

The SOTI Identity Lookup Provider in JoinNow requires a MobiControl API user with read access to device records and device group membership. No write permissions are required. The API credentials (server URL, client ID, and client secret) are entered in JoinNow when configuring the SOTI Identity Lookup Provider. SecureW2 reads device enrollment state and group membership; it does not modify any MobiControl records.

Is user interaction required during certificate enrollment?

No. Enrollment is zero-touch. MobiControl pushes the SCEP certificate profile to managed devices automatically as part of the device configuration policy. The device initiates the SCEP request, the Policy Engine validates it against MobiControl, and the certificate is issued and stored on the device all without the device operator seeing a prompt or taking any action. For large fleet rollouts, enrollment processes concurrently across devices and does not require serialized provisioning.

Ready to Connect SecureW2 to SOTI MobiControl?

Connect with our integration specialists to implement this solution in your environment and transform your security posture.