The Challenge
An industrial robotics company knew it needed to replace pre-shared keys with certificate-based Wi-Fi, but organizational changes and team turnover shelved the project. Then, a major contract from the U.S. Navy made certificate-based authentication a priority — now. The team had just days to meet network security compliance requirements or risk losing the contract.
Two additional challenges complicated matters:
Three MDM platforms: Intune, Jamf, and JumpCloud meant three different certificate delivery mechanisms to integrate with no gap allowed during the transition.
Global distribution: Multiple offices across several countries running Cisco Meraki infrastructure meant, combined with the time crunch, the deployment needed to work everywhere, not just as a single-site pilot.
The company decided to work with SecureW2 because the platform could integrate with all three MDMs from a single PKI instance and support Okta as the identity provider, matching the infrastructure the team already ran.
The Solution
The SecureW2 team got to work immediately. Within 48 hours of signing, the company had certificate-based Wi-Fi running across a multi-MDM environment spanning 5 offices on 3 continents. Here’s how:
Day 1
SecureW2 configured the JoinNow Connector PKI for Windows devices through Intune. The SecureW2 team also set up Cloud RADIUS with RadSec (RADIUS over TLS) for encrypted authentication between Meraki APs and the RADIUS server.
RadSec added transport-layer encryption to the RADIUS traffic, a requirement that aligned with the defense compliance posture. The senior IT systems engineer tested on a recently wiped Windows laptop, and the test was a success: the certificate arrived automatically, and the device connected to the EAP-TLS SSID without manual intervention.
Day 2
SecureW2 configured certificate delivery through for JumpCloud and through Jamf Pro for macOS. The team also set up JoinNow MultiOS self-enrollment for Linux devices with no MDM coverage, providing a browser-based onboarding URL that Linux users accessed directly.
The Meraki test SSID had been created before the first call, so the IT team was ready to validate immediately. Five offices across multiple countries, including a location in the UAE, all ran the same Meraki infrastructure and received the same RADIUS and certificate configurations.
The Results
- Contract to live certificates in one day: Intune configuration completed the day after the deal closed, with certificates auto-deploying to Windows devices
- 48-hour deployment across three MDMs: Intune (Day 1) and Jamf (Day 2) configured in back-to-back sessions, with JoinNow MultiOS covering unmanaged Linux devices
- Navy compliance addressed: Certificate-based authentication satisfies the defense contract’s security requirements
- RadSec encryption: RADIUS traffic between Meraki APs and Cloud RADIUS runs over TLS for transport-layer security beyond standard RADIUS
With the initial deployment live, the company plans to migrate remaining devices off JumpCloud and onto Intune or Jamf Pro, keeping the same certificate authority chain throughout the transition. Guest Wi-Fi access is the next planned addition, extending the platform beyond employee authentication.