Fleet MDM manages the devices. SecureW2 issues the certificates. ACME with hardware binding for Apple fleets. SCEP for macOS, Windows, Linux, ChromeOS, iOS, and Android. Cloud RADIUS enforces access at every authentication; no manual revocation required.
Overview
Fleet MDM, built on the open-source platform osquery, manages macOS, iOS, iPadOS, Windows, Linux, ChromeOS, and Android devices from a single control plane. SecureW2 integrates as the external certificate authority, automatically handling digital certificates across devices without requiring manual IT intervention.
Fleet offers two enrollment methods. For Apple devices, it pushes a .mobileconfig profile via Apple MDM with an ACME payload and HardwareBound: true, generating the private key in the Secure Enclave that never leaves the hardware. For other platforms, Fleet provides SCEP credentials via its built-in SCEP CA, allowing devices to request certificates directly from SecureW2, generating keys on-device.
JoinNow Cloud RADIUS enforces network access at authentication, checking Fleet enrollment status. Devices removed from Fleet lose network access on the next connection attempt without manual intervention.
Fleet pushes a signed .mobileconfig profile via Apple MDM. The device generates a 384-bit EC private key inside the Apple Secure Enclave and requests a certificate from SecureW2’s ACME API. The key never leaves the hardware, not even during enrollment.
Fleet distributes SecureW2 SCEP credentials to every device it manages, macOS, Windows, Linux, ChromeOS, iOS, and Android. Devices request certificates directly from JoinNow Dynamic PKI. At authentication, Cloud RADIUS validates the certificate and checks the device’s live Fleet enrollment state before granting network access.
The SecureW2 FleetDM's integration delivers certificate-based authentication for managed device fleets, with no user interaction, shared secrets, or manual provisioning. JoinNow issues certificates automatically through FleetDM's configuration profiles, using Apple Managed Device Attestation to bind credentials to verified Apple hardware via ACME or Dynamic SCEP. Once enrolled, Cloud RADIUS enforces access policy against live FleetDM posture data, revoking access immediately if a device falls out of management or fails a compliance check.
FleetDM's device group membership and compliance status determine VLAN assignment during authentication via Cloud RADIUS. No manual VLAN assignment is required; devices are placed in the correct network segment automatically based on their current FleetDM state. A managed, compliant device in the Corporate Devices Smart Group receives full corporate access. A non-compliant device is placed in a restricted VLAN with internet-only access. A device not found in FleetDM is denied access entirely. Because VLAN assignment is evaluated at every authentication, changes to FleetDM group membership take effect at the next connection attempt. No certificate reissuance or profile update is required.
Frequently Asked Questions
Connect with our integration specialists to implement this solution in your environment and transform your security posture.