The Challenge
One of the nation’s leading early childhood education providers operates more than 2,000 centers across the United States.
A small, centralized IT team manages the entire operation remotely. When Wi-Fi goes down at any individual center, the team has to detect and resolve the issue without being on-site.
As Wi-Fi access depends on certificate-based authentication, a certificate enrollment failure at any center impacts operations.
The organization uses System Center Configuration Manager (SCCM) as its primary device management tool but is moving newer devices to Intune.
This means two parallel certificate enrollment methods — Web Services for Trust Enablement Protocol (WSTEP) for SCCM and Simple Certificate Enrollment Protocol (SCEP) for Intune — must coexist without disrupting the production network at any center.
When Microsoft released KB5014754, requiring strong certificate mapping for Active Directory authentication, the organization faced a fleet-wide certificate re-enrollment across 10,800 devices.
In addition, without centralized RADIUS event monitoring, the IT team had no real-time alerting when certificate-based authentication failed at a center.
To address their decentralized needs, the organization chose a cloud-hosted public key infrastructure (PKI) and RADIUS platform that could be managed entirely by a centralized team. Key to their decision was the ability to manage certificates through SCCM task sequences and Intune SCEP profiles without touching hardware at 2,000+ locations.
The Solution
The IT team wrote custom PowerShell scripts that trigger certificate enrollment requests against the SecureW2 API gateway, deploying them through SCCM task sequences to devices across the country. For newer devices on Intune, the team configured SCEP profiles that enroll certificates directly from the SecureW2 cloud PKI.
Both enrollment paths authenticate against Cloud RADIUS with Microsoft Entra ID providing the identity attributes embedded in each certificate.
For the KB5014754 re-enrollment, the SecureW2 support team guided the organization through updating WSTEP certificate templates to include new Subject Alternative Name attributes required for strong certificate mapping. The IT team then rolled out re-enrollment scripts through SCCM completing the compliance update without service disruption.
The most recent phase focused on shipping RADIUS authentication events to external monitoring platforms.
The IT security team explored options for sending RADIUS events to Datadog or Splunk for automated alerts for Wi-Fi authentication failures at any center— turning a reactive troubleshooting model into proactive detection.
The Results
- 2,000+ centers secured: Every early learning center across states runs certificate-based 802.1X for Wi-Fi.
- 10,800 devices enrolled: Device enrollment across both SCCM and Intune with two parallel enrollment paths
- KB5014754 compliant: Fleet-wide certificate re-enrollment completed without service disruption at any center.
- Proactive monitoring: RADIUS event monitoring pipelines in development for proactive alerting, with SCCM-to-Intune migration ongoing.
As the organization transitions more of its device fleet from SCCM to Intune, the SCEP enrollment path will carry a growing share of new devices.
The SecureW2 RADIUS monitoring pipeline, once live, will give the centralized IT team real-time visibility into every center’s Wi-Fi health — a capability that transforms how a small team supports 2,000+ locations.