Back to Customer Stories
Professional Services / Engineering Consulting
1min read
August 7, 2026

A National Engineering Firm Secures 6,000 Devices Across a Multi-MDM Enterprise with Certificate-Based Authentication

At a Glance
Industry Professional Services / Engineering Consulting
Use Case 802.1X certificate-based Wi-Fi across all device types
Products Cloud RADIUS, Dynamic PKI, JoinNow Platform
Key Result 6,000 devices across three MDM platforms and four operating systems moved to certificate-based authentication

The Challenge

A national engineering firm with around 3,000 employees and offices in numerous states, found numerous security vulnerabilities in its legacy password-based Wi-Fi authentication system. For a firm handling sensitive federal projects, shared credentials created an unacceptable attack surface that needed to be eliminated.

The environment added complexity: Microsoft Intune managed Windows devices, IBM MaaS360 handled macOS, and Apple Business Manager covered mobile enrollment. Any certificate-based solution had to integrate with all three MDM platforms without requiring separate workflows for each.

The firm needed a vendor-neutral platform that could absorb the complexity of three MDM integrations and four operating systems under a single authentication architecture, while also providing trusted, managed Wi-Fi access for thousands of employees.

The Solution

The firm selected the SecureW2 JoinNow Platform for its roughly 6,000 devices, adding a managed PKI, cloud RADIUS, and Entra ID integration to secure their network. Both Mac and Windows moved to 802.1X certificate-based Wi-Fi on schedule.

Microsoft Intune handles automated certificate enrollment for the Windows fleet, while a pivot to SCEP-based enrollment through Apple Business Manager kept the upgrade moving swiftly without the need for an architecture redesign.

The Results

  • Windows, iOS, and Android devices enrolled and authenticating: A heterogenous device environment moved to a secure, certificate-based Wi-Fi access platform with support for multiple MDMs.
  • macOS integration path identified: When MaaS360 delivery hit a snag, the team pivoted to alternative enrollment methods — leveraging the SecureW2 platform’s flexibility across multiple delivery paths.
  • Enterprise-scale deployment in a multi-MDM environment: The 6,000-device license across three MDM platforms and four operating systems represents one of the more complex enterprise deployments in the SecureW2 customer base.

With three platforms fully authenticated and the macOS path identified, the firm is positioned to complete its migration to passwordless Wi-Fi across the entire device fleet. The multi-MDM architecture now serves as a template for future office expansions, with Cloud RADIUS removing the need for on-premises authentication hardware at each location.

Learn More About SecureW2

Explore SecureW2's trust model, dive into our platform and product details or read more success stories.

Why SecureW2

Establish continuous trust with Dynamic PKI and Cloud RADIUS. Enforce access based on live identity, device posture, and risk context.

  • Passwordless authentication that can’t be phished
  • Works with your IdP, MDM, and security stack
  • Real-time policy engine for dynamic access control
Explore the Platform

Get the essentials on the products that power continuous enforcement.

Knowledge Base Articles

Explore practical guidance from engineers and admins deploying SecureW2.

  • Setup and configuration tutorials
  • Integration best practices with IdPs and MDMs
  • Troubleshooting guides for PKI and RADIUS