The Challenge
Until recently, a globally ranked top-20 private equity and venture capital investment firm relied on pre-shared keys and passwords to secure the company’s Wi-Fi network.
This solution was not sufficiently secure for an organization handling sensitive deal data, term sheets, and portfolio company financials daily. The firm decided to transition to certificate-based authentication, with a few key specifications.
The company required a fully cloud-hosted solution, with zero on-premises infrastructure. The mixed device environment — Windows on Intune, Mac on Jamf Pro, plus BYOD — also required a unified certificate enrollment approach across both MDMs. Beyond that, it was important for the firm to find an intuitive, easy-to-use solution that would deliver a high level of security without excess complexity.
The Solution
The firm’s security consultants worked with the SecureW2 technical team to design and validate a certificate-based authentication solution, assessing the managed PKI architecture, certificate enrollment automation, and cloud-based RADIUS integration.
Certificate enrollment runs through two paths: SCEP-based enrollment for Windows through Intune and for Mac through Jamf Pro. Certificate attributes are customized to include template name and OID values for device identification — a detail that reflects the firm’s sophisticated security requirements.
Unmanaged personal devices enroll through a BYOD workflow integrated with Entra ID, using identity provider authentication to bind each certificate to a verified user.
SecureW2 support engineers worked through Intune and Jamf configuration, BYOD enrollment testing, and RADIUS policy validation across the full device fleet.
The Results
- 825 devices enrolled: certificate-based 802.1X authentication deployed across Intune, Jamf Pro, and BYOD
- Cloud-native deployment: no on-premises infrastructure required
- Unified enrollment across all device types: Windows, Mac, and personal BYOD devices managed through a single certificate-based workflow
- Eliminated pre-shared key vulnerabilities: sensitive deal data, term sheets, and portfolio financials now protected by certificate-based authentication