The Challenge
Switching identity providers is hard enough without worrying about whether 1,850 devices will stay connected to the corporate network.
A home improvement fintech was migrating away from Active Directory (AD) at a time when Microsoft had deprecated certain authentication methods.
Running Intune for Windows and Kandji for macOS meant maintaining two separate Simple Certificate Enrollment Protocol (SCEP) enrollment configurations, each with its own profile structure and troubleshooting requirements.
Over time, device lifecycle events — retirements, re-enrollments, re-images — left behind certificates that no longer corresponded to active devices, leaving the client with more enrolled devices than the company actually managed.
The Solution
The SecureW2 platform addressed the company’s dual mobile device management (MDM) and certificate management requirements and supported future Okta-based device trust initiatives.
Windows and macOS devices receive user-based certificates through Intune and Kandji SCEP profiles, respectively, for authentication against SecureW2 Cloud RADIUS for Wi-Fi access. Okta serves as the identity provider, with certificate attributes tied to verified user identities rather than device records.
The SecureW2 team worked with the company to audit enrolled certificates, identify stale entries from retired or re-imaged devices, and clean up the device inventory, resolving a discrepancy of several hundred devices between the portal count and the actual fleet size.
The SecureW2 platform provides real-time identity lookups during RADIUS authentication, pulling user attributes and device compliance status from Okta to inform network access decisions. This capability is especially valuable as the organization completes its migration away from Active Directory.
The Results
- 1,850 devices secured: Certificate-based Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) across both Windows (Intune) and macOS (Kandji) secured the company’s device fleet.
- Stale certificates cleared: Multi-session cleanup resolved the device count discrepancy between the portal and actual fleet.
- AD migration supported: The SecureW2 certificate and identity infrastructure supported the transition to Okta as the primary trust anchor for network access.
As the Active Directory migration completes, the company will rely entirely on Okta and SecureW2 Cloud RADIUS as the identity and access backbone for its network. This sets the team up to add device compliance checks and conditional access policies as the security posture matures.