The Challenge
During a routine compliance review, a restaurant group discovered that three payment terminals at drive-in locations had gone haywire, with one device autonomously issuing itself 5,500 certificates. Across the three terminals, the total exceeded 16,000 rogue certificates — blowing past license counts and creating a compliance nightmare.
The company had relied on pre-shared keys to authenticate restaurant devices to Wi-Fi. PSK credentials, once shared, offer no device-level visibility or revocation capability. At hundreds of locations spanning corporate offices, drive-in restaurants, and casual dining brands, that risk multiplied. To remedy the security gap, the company mandated that all restaurant devices — including Android tabletop tablets at casual dining locations — authenticate via EAP-TLS certificates instead.
Those Android tablets presented a unique problem. They had no traditional MDM integration and no SCEP support, meaning standard certificate enrollment paths did not apply. The company needed a way to push certificates to thousands of tablets through a custom cloud-based management system.
The company had previously used a different certificate provider but did not want on-premises RADIUS. A cloud-native PKI and RADIUS bundle that could scale to 50,000+ devices across multiple brands — and support non-standard enrollment for devices outside traditional MDM — narrowed the field to one vendor.
The Solution
The deployment with SecureW2 unfolded in three phases over four years, evolving from a standard corporate rollout into a multi-brand, cross-environment certificate-based authentication program.
In the first phase, the company deployed JoinNow Dynamic PKI and JoinNow Cloud RADIUS to support corporate devices, including Windows laptops and iOS devices managed through Workspace ONE. Certificate enrollment was handled through SCEP, with EAP-TLS used to authenticate devices to Cloud RADIUS over WPA2-Enterprise.
This initial rollout established the foundation for certificate-based authentication at scale, growing from 4,000 to approximately 13,000 devices.
The second phase expanded the deployment into drive-in and restaurant environments, bringing payment terminals and additional store devices into scope. During a compliance audit, 16,000 rogue certificates tied to payment terminals were identified and revoked, prompting a 9,000-device true-up that brought the environment to approximately 21,250 licensed devices. At this stage, the company operated separate SecureW2 tenants for corporate and restaurant brands, each configured with distinct certificate policies and enrollment settings.
The third phase focused on extending certificate-based authentication to a fleet of Android tablets used across casual dining locations spanning 400+ sites. Because the tablet vendor’s cloud-based management platform did not support SCEP, the team implemented a REST API-based certificate enrollment path for them. Through this approach, an orchestrator requests certificates via the REST API on behalf of each device, which initially connects to a guest network before receiving and installing the certificate through the management platform. This enables EAP-TLS authentication without relying on traditional MDM-based enrollment.
The infrastructure now supports a path toward supporting enrollment and management for 50,000–70,000 devices across brands.
The Results
- Continual certificate growth: The company scaled from 4,000 to 22,150+ licensed devices over four years.
- PSK eliminated: EAP-TLS certificate-based authentication replaced PSK across corporate and restaurant device fleets.
- 16,000 phantom certificates identified and revoked: Automated phantom certificates tied to rogue payment terminals were discovered and revoked from the system.
- First-of-its-kind REST API certificate enrollment path built: SecureW2 built a solution to support certificate enrollment for non-standard Android tablets.
- Expanding toward 50,000-70,000 total devices across all brands: Growth continues, supported by an OEM/security-module relationship with tablet manufacturers in development.
With the REST API path in production, the company is exploring an OEM relationship with the tablet manufacturer to extend certificate-based authentication to other restaurant brands on the same platform. What started as a corporate Wi-Fi project now shapes how an entire category of restaurant devices connects to the network.