SecureW2 auto-enrolls and manages certificates using ServiceNow device data. Device attributes flow from ServiceNow into certificate issuance and Cloud RADIUS policy so your network access decisions reflect your actual device inventory, not a snapshot from enrollment day.
Overview
SecureW2 is the PKI and RADIUS layer for ServiceNow environments. It auto-enrolls and manages certificates for network access control by leveraging ServiceNow’s device management capabilities. The combined platform enables real-time network policy enforcement based on device attributes and user context, supporting granular network segmentation and dynamic VLAN assignment.
ServiceNow acts as the device authority. SecureW2 consumes ServiceNow device context attributes, user context, and posture state to drive certificate issuance through Dynamic SCEP and to inform Cloud RADIUS access decisions at the moment a device connects. Certificates are fully customizable: any standard or custom attribute sourced from ServiceNow (department, title, group membership) can be encoded into the credential.
The admin deploys a configuration profile through ServiceNow. The device initiates a SCEP certificate request to SecureW2, which verifies the request against ServiceNow device data before issuing a device-bound certificate. The certificate installs automatically and is used for 802.1X / EAP-TLS network authentication.
The device presents its certificate to the network infrastructure. The access point or VPN gateway forwards the authentication request to SecureW2 Cloud RADIUS, which evaluates the certificate against ServiceNow device attributes and posture state before returning an ACCEPT or REJECT and assigning the appropriate VLAN.
When a device is removed from ServiceNow inventory or its posture state changes to marked non-compliant, decommissioned, or offboarded, the Webhook-driven sync propagates the change to SecureW2 immediately. The device's certificate is revoked without waiting for the certificate's natural expiration or a manual admin action.
At the next connection attempt, Cloud RADIUS validates the certificate against SecureW2's revocation list and returns a RADIUS REJECT, removing the device from the network in real time. No help desk ticket, no manual VLAN change, no waiting for the certificate to expire; access ends the moment ServiceNow signals the device is no longer trusted.
This revocation loop applies to all managed device types: laptops, mobile devices, shared workstations, and works across Wi-Fi, VPN, and any other network infrastructure connected to Cloud RADIUS. The full lifecycle from enrollment through revocation is driven by ServiceNow device state.
JoinNow Cloud RADIUS acts as the RADIUS server for your network infrastructure. At authentication time, the policy engine validates the device's certificate and evaluates its current posture state sourced from ServiceNow, returning a RADIUS ACCEPT or REJECT to the access point or VPN gateway.
The Webhook-based API sync between ServiceNow and SecureW2 ensures that device attribute and posture changes in ServiceNow propagate to Cloud RADIUS in real time. A device removed from ServiceNow or marked non-compliant will have its access rejected at the next authentication event, no manual intervention required.
Frequently Asked Questions
Connect with our integration specialists to implement this solution in your environment and transform your security posture.