The Challenge
A healthcare IT company builds electronic health record (EHR) and practice management software for medical practices across the United States, covering more than eight specialties with over 4000 staff and contractors spread across the world.
The in-house IT team manages a complex device environment with over 4000 endpoints across a mixed Mac and Windows fleet. They needed to enroll devices in this multi-OS system across geographies.
The client needed a Certificate Authority that could serve both operating systems through their respective MDM platforms — Jamf Pro for macOS and Microsoft Intune for Windows— without requiring separate certificate infrastructure for each. Managing dual CAs would double the administrative burden for a team already juggling multiple identity and device management systems.
Beyond Wi-Fi, the company needed to provision device certificates through an external CA to support Okta Device Access and endpoint management.
The Solution
SecureW2 met the requirements for Okta external CA integration, multi-OS support through both Jamf Pro and Intune, and cloud-native delivery.
The healthcare EHR company deployed the SecureW2 JoinNow Connector PKI and Cloud RADIUS bundle.
SecureW2 configured Cloud PKI as an external Certificate Authority in Okta. This supported both Okta Device Access and broader endpoint management of the macOS fleet through Jamf Pro.
The SecureW2 team deployed Okta certificates for Windows devices through Intune, ensuring both MDM platforms connect to the same cloud PKI for unified certificate lifecycle management.
As an added layer of security, the company configured RADSEC with its Cisco Meraki wireless network. RADSEC wraps RADIUS traffic in TLS, adding a layer of protection to every authentication event, a hardening step that reflects a mature security posture.
Printers and similar non-user hardware receive signed certificates through a dedicated SecureW2 intermediate CA, extending certificate-based identity beyond user endpoints to the full device environment.
The Results
- Unified certificate lifecycle: Over 4,000 devices managed under a unified certificate lifecycle across macOS (Jamf Pro) and Windows (Intune).
- Secure Wi-Fi authentication: RADSEC in production with Cisco Meraki for encrypted RADIUS transport on every authentication event.
- Dual-MDM integration: Jamf Pro and Intune both connect to the same cloud PKI without separate infrastructure.
- Intermediate CA for hardware: Printers and non-user devices authenticate with signed certificates.
The company continues expanding certificate-based Wi-Fi across additional locations and deploying Okta certificates to its growing Windows fleet. The SecureW2 platform now covers Wi-Fi authentication, RADSEC, and hardware certificates.