Back to Customer Stories
Technology / Application Security
1min read
August 1, 2026

How a $20B Application Security Company Upgraded Certificate Authentication for 10,000 Devices

At a Glance
Industry Technology / Application Security
Use Case Wi-Fi 802.1X, conditional access, wired network authentication
Products Cloud RADIUS, Dynamic PKI, JoinNow Platform
Key Result Improved security posture via completed and planned security upgrades, including dynamic SCEP, CrowdStrike implementation and wired certificate auth.

The Challenge

A large global application security company has more than 6,000 employees and 10,000 devices to secure. They already used the SecureW2 JoinNow Connector PKI, but evolving needs pressed their IT department to consider an expansion of certificate-based network access. One factor motivating the upgrade: stale device certificates were accumulating on retired or re-imaged machines thanks to static SCEP.

The current deployment supported both Windows and iOS devices through Intune and Jamf respectively, and ran conditional access policies for device authentication using the SecureW2 platform. Now, the client was considering shifting from device-based certificates to user-based certificates for its Windows fleet as well as expanding certificate-based access to wired devices. Automatic certificate revocation to forestall stale certificate build-up was another obvious need, and a coming Crowstrike implementation opened up additional possibilities for risk-based certificate actions.

As these challenges and opportunities loomed, the team also had to confront the departure of their old team lead, who was intimately familiar with their deployment, leaving an institutional knowledge gap.

The Solution

The SecureW2 platform’s operational simplicity meant a new team could inherit the infrastructure, understand the architecture, and build on it — without starting over or bringing in the original architect.

Certificates issued through the SecureW2 ManagedPKI authenticate 10,000 devices for Wi-Fi access via 802.1X and support conditional access policy enforcement. Windows devices receive certificates through Intune — including Cloud PCs provisioned via Autopilot — while Macs receive certificates through Jamf. Crowdstrike will cover endpoint security, while Aruba wireless infrastructure with ClearPass handles RADIUS forwarding on the network side.

The IT team performed a manual bulk revocation exercise that removed over 1,000 inactive device entries. Moving forward, the static SCEP configuration on the Jamf side will be upgraded to dynamic SCEP for improved certificate lifecycle management, meaning no more manual revocations in the future

Two additional new deployments are on the roadmap: wired network 802.1X using the same certificates already used for Wi-Fi and a shift from device certificates to user certificates for the Windows fleet.

The Results

  • 10,000 devices secured: Certificate-based 802.1X deployed across the full Windows and Mac fleet.
  • Active expansion: Extended deployment into wired network authentication, user-based certificates, and CrowdStrike integration.
  • Two additional deployments planned: for the wired network 802.1X using the same certificates already used for Wi-Fi and a shift from device certificates to user certificates for the Windows fleet.

With wired 802.1X on the roadmap, the deployment continues to grow in scope.

Learn More About SecureW2

Explore SecureW2's trust model, dive into our platform and product details or read more success stories.

Why SecureW2

Establish continuous trust with Dynamic PKI and Cloud RADIUS. Enforce access based on live identity, device posture, and risk context.

  • Passwordless authentication that can’t be phished
  • Works with your IdP, MDM, and security stack
  • Real-time policy engine for dynamic access control
Explore the Platform

Get the essentials on the products that power continuous enforcement.

Knowledge Base Articles

Explore practical guidance from engineers and admins deploying SecureW2.

  • Setup and configuration tutorials
  • Integration best practices with IdPs and MDMs
  • Troubleshooting guides for PKI and RADIUS