The SecureW2 platform provides the PKI and RADIUS layer required to secure Google Workspace environments. When the Google Admin Console pushes a SCEP profile to a managed Chromebook, SecureW2 validates the user identity against Google Workspace and automatically issues a digital certificate without user interaction. JoinNow Cloud RADIUS then enforces access policies in real time by performing a live identity lookup at every authentication.
Overview
Automate certificate-based authentication for Chromebook fleets and Google-managed devices without user interaction or manual provisioning. When the Google Admin Console pushes SCEP certificate profiles to managed devices via Chrome Enterprise policy, the SecureW2 JoinNow platform validates identity against Google Workspace and issues a digital certificate tied to the specific user or hardware. Google Workspace serves as both the MDM for deployment and the authoritative identity provider for ongoing access control.
JoinNow Cloud RADIUS performs live identity lookups against Google Workspace at every authentication event, ensuring that network access decisions reflect real-time status, such as organizational unit membership or account status. If an administrator suspends a user or removes a device from Workspace, SecureW2 restricts network access at the next connection attempt.
Google Admin Console pushes an SCEP certificate profile to managed Chromebooks. SecureW2 validates the requesting user or device against Google Workspace before issuing a certificate. No user interaction is required at any step.
At every authentication event, Cloud RADIUS queries Google Workspace to verify that the user is still active and belongs to the correct organizational unit. VLAN assignment is determined by current Workspace OU membership; no static policy configuration per device is required.
SecureW2 Cloud RADIUS supports Google Workspace as a cloud identity provider for real-time attribute lookup during EAP-TLS authentication. This ensures network access decisions are based on current Google Workspace identity data, not static attributes in the certificate.
At each authentication event, the JoinNow Policy Engine queries the Google Workspace Directory API to verify the user’s account status, organizational unit membership, and group membership. It then applies the matching network access policy and returns the appropriate RADIUS attributes, such as VLAN and access level.
The attributes available for policy matching include account status (active, suspended, or deleted), organizational unit path, Google Workspace group membership, and device enrollment status. If a user account is suspended in Google Workspace, Cloud RADIUS detects this and denies access during the next connection attempt without requiring certificate revocation or MDM profile update.
Google Workspace organizational unit membership determines VLAN assignment at authentication time via Cloud RADIUS. Static VLAN assignments in certificates or MDM profiles are unnecessary. Devices automatically receive the correct network segment based on their current Workspace OU. Active staff accounts can be mapped to full corporate access VLANs, students to filtered-internet VLANs, and contractors to internet-only VLANs. Suspended accounts and users not found in Workspace are denied access. This is useful in K-12 and higher education environments where students, staff, and faculty have distinct access requirements and are organized into separate OUs.
VLAN assignment is evaluated at every authentication, so changes in Workspace OU membership take effect at the next connection attempt. A student account moved to the Staff OU receives staff-level network access on the next reconnect without certificate reissuance or profile update.
Frequently Asked Questions
Connect with our integration specialists to implement this solution in your environment and transform your security posture.