Back to Customer Stories
Technology / Identity & Access Management
1min read
July 19, 2026

How a Leading Digital Security Firm Chose SecureW2 Certificate-Based Authentication for Its Own 20,000-Device Network

At a Glance
Industry Technology / Identity & Access Management
Use Case Corporate Wi-Fi 802.1X, BYOD enrollment, managed device certificate deployment
Products Cloud RADIUS, Dynamic PKI, JoinNow Platform
Key Result A rigorous, year-long head-to-head comparison resulted in the client choosing SecureW2 to secure 20,000 devices across three OS platforms.

The Challenge

A leading digital security company serving thousands of organizations worldwide wanted to improve certificate-based authentication for its 20,000-device network. With a large enterprise network, migrating to a new system proved complicated.

Its previous certificate and RADIUS solution lacked integrations with Splunk and CrowdStrike — tools the company relied on for security visibility. The team needed a PKI solution that could ingest real-time risk signals from their identity platform and feed authentication data into their security stack.

The company’s own security policies created integration requirements that few vendors could meet. For example API tokens with Super Admin access were prohibited, and instead the team required OAuth-based, least-privilege connections for any third-party integration. The production environment also had limited options for real-time certificate revocation when employees were terminated or suspended.

The device fleet spanned three distinct enrollment paths: Jamf Pro for Mac (the majority), Microsoft Intune for Windows, and a BYOD workflow for personal iOS devices. Each path required its own certificate template, enrollment policy, and RADIUS configuration. Adding difficulty, the previous PKI vendor had an existing external CA connection in Jamf.

The Solution

The company ran a full proof of concept over a 12-month period, comparing SecureW2 against the incumbent solution. A staff network engineer on the corporate platform engineering team led the proof of concept, running tests across all three enrollment paths.

The deployment covered three enrollment paths: dynamic SCEP for Mac through Jamf Pro, WSTEP and SCEP-based enrollment for Windows through Intune, and self-service certificate enrollment for BYOD iOS devices with identity provider integration. The company’s own identity platform was configured for SAML-based login to the SecureW2 management console.

For auto-revocation, the team explored Workflows with a custom connector as an alternative to event hooks, since the production environment had maxed out its 25-hook capacity.

The Results

  • Move to Cloud RADIUS for certificate-based authentication after a rigorous technical evaluation
  • 20,000 devices across three OS platforms under certificate-based authentication
  • Opportunity to drive product innovation and joint go-to-market opportunities through partnership with leader in digital security

Learn More About SecureW2

Explore SecureW2's trust model, dive into our platform and product details or read more success stories.

Why SecureW2

Establish continuous trust with Dynamic PKI and Cloud RADIUS. Enforce access based on live identity, device posture, and risk context.

  • Passwordless authentication that can’t be phished
  • Works with your IdP, MDM, and security stack
  • Real-time policy engine for dynamic access control
Explore the Platform

Get the essentials on the products that power continuous enforcement.

Knowledge Base Articles

Explore practical guidance from engineers and admins deploying SecureW2.

  • Setup and configuration tutorials
  • Integration best practices with IdPs and MDMs
  • Troubleshooting guides for PKI and RADIUS