Back to Customer Stories
Childcare / Education
2min read
July 27, 2026

How a Childcare Provider Deployed Certificate-Based Authentication Across 2,000+ Locations

At a Glance
Industry Childcare / Education
Use Case Certificate-based Wi-Fi at 2,000+ early learning centers, dual-MDM enrollment (SCCM and Intune)
Products Cloud RADIUS, Dynamic PKI
Key Result Certificate-based 802.1X running continuously across 2,000+ locations without centralized on-site IT staff

The Challenge

One of the nation’s leading early childhood education providers operates more than 2,000 centers across the United States.

A small, centralized IT team manages the entire operation remotely. When Wi-Fi goes down at any individual center, the team has to detect and resolve the issue without being on-site.

As Wi-Fi access depends on certificate-based authentication, a certificate enrollment failure at any center impacts operations.

The organization uses System Center Configuration Manager (SCCM) as its primary device management tool but is moving newer devices to Intune.

This means two parallel certificate enrollment methods — Web Services for Trust Enablement Protocol (WSTEP) for SCCM and Simple Certificate Enrollment Protocol (SCEP) for Intune — must coexist without disrupting the production network at any center.

When Microsoft released KB5014754, requiring strong certificate mapping for Active Directory authentication, the organization faced a fleet-wide certificate re-enrollment across 10,800 devices.

In addition, without centralized RADIUS event monitoring, the IT team had no real-time alerting when certificate-based authentication failed at a center.

To address their decentralized needs, the organization chose a cloud-hosted public key infrastructure (PKI) and RADIUS platform that could be managed entirely by a centralized team. Key to their decision was the ability to manage certificates through SCCM task sequences and Intune SCEP profiles without touching hardware at 2,000+ locations.

The Solution

The IT team wrote custom PowerShell scripts that trigger certificate enrollment requests against the SecureW2 API gateway, deploying them through SCCM task sequences to devices across the country. For newer devices on Intune, the team configured SCEP profiles that enroll certificates directly from the SecureW2 cloud PKI.

Both enrollment paths authenticate against Cloud RADIUS with Microsoft Entra ID providing the identity attributes embedded in each certificate.

For the KB5014754 re-enrollment, the SecureW2 support team guided the organization through updating WSTEP certificate templates to include new Subject Alternative Name attributes required for strong certificate mapping. The IT team then rolled out re-enrollment scripts through SCCM completing the compliance update without service disruption.

The most recent phase focused on shipping RADIUS authentication events to external monitoring platforms.

The IT security team explored options for sending RADIUS events to Datadog or Splunk for automated alerts for Wi-Fi authentication failures at any center— turning a reactive troubleshooting model into proactive detection.

The Results

  • 2,000+ centers secured: Every early learning center across states runs certificate-based 802.1X for Wi-Fi.
  • 10,800 devices enrolled: Device enrollment across both SCCM and Intune with two parallel enrollment paths
  • KB5014754 compliant: Fleet-wide certificate re-enrollment completed without service disruption at any center.
  • Proactive monitoring: RADIUS event monitoring pipelines in development for proactive alerting, with SCCM-to-Intune migration ongoing.

As the organization transitions more of its device fleet from SCCM to Intune, the SCEP enrollment path will carry a growing share of new devices.

The SecureW2 RADIUS monitoring pipeline, once live, will give the centralized IT team real-time visibility into every center’s Wi-Fi health — a capability that transforms how a small team supports 2,000+ locations.

Learn More About SecureW2

Explore SecureW2's trust model, dive into our platform and product details or read more success stories.

Why SecureW2

Establish continuous trust with Dynamic PKI and Cloud RADIUS. Enforce access based on live identity, device posture, and risk context.

  • Passwordless authentication that can’t be phished
  • Works with your IdP, MDM, and security stack
  • Real-time policy engine for dynamic access control
Explore the Platform

Get the essentials on the products that power continuous enforcement.

Knowledge Base Articles

Explore practical guidance from engineers and admins deploying SecureW2.

  • Setup and configuration tutorials
  • Integration best practices with IdPs and MDMs
  • Troubleshooting guides for PKI and RADIUS