The Challenge
A new state task force opening additional locations in Florida needed to build a secure wireless environment from scratch with a three-person IT team and no existing network infrastructure. The team faced the challenge of selecting, purchasing, and deploying every component of the network stack simultaneously.
Physical RADIUS infrastructure would have required redundant hardware at each location, an untenable cost for a new agency with constrained budgets. At the same time, password-based Wi-Fi with Entra ID as the identity provider would mean every password change triggered authentication failures and support tickets, something three people could not handle.
The agency needed a cloud-native authentication stack that could deploy without on-premises hardware, scale across locations, and run with minimal management.
SecureW2 Cloud RADIUS and managed public key infrastructure (PKI) met all three requirements.
The Solution
Ease of implementation, affordability, and the elimination of on-premises hardware were deciding factors for deploying the SecureW2 JoinNow platform.
The deployment paired Cloud RADIUS with managed PKI integrated with Microsoft Intune for automated certificate enrollment and Entra ID for identity-backed certificate issuance.
Cisco Meraki access points handle the wireless layer, authenticating devices via Extensible Authentication Protocol-Transport Layer Security (EAP-TLS).
The organization plans to expand to multiple locations, with network security deployment made easy by the fact that adding a new location requires only a Meraki access point linked to the same Cloud RADIUS instance.
The Results
- Cloud-native secure wireless from day one: The organization launched with certificate-based authentication as its default; every device authenticates with a digital certificate, not a password.
- No on-premises RADIUS hardware: Cloud RADIUS delivered the availability the organization required without capital expense at each location.
- Expanded use case vision: The SecureW2 platform created a foundation for extending certificate-based authentication to VPN access and Entra ID conditional access.
As the agency expands, each new location connects to the same Cloud RADIUS and PKI infrastructure. The three-person IT team can onboard additional facilities without adding staff or deploying hardware.