The Challenge
An agency operates transportation and trade infrastructure across two states, including airports bridges, and a rail system.
Its Cisco ISE deployment caused endless connectivity support tickets. Devices failed to authenticate, users called the help desk, and the support inbox stayed full. Beyond the operational pain, the authority identified a vulnerability in its Wi-Fi authentication model that required remediation. For an agency responsible for national infrastructure, a weakness in network access control has ramifications that extend far beyond IT operations. Fixing the issue became a leading priority.
The authority also needed a guest Wi-Fi solution serving visitors across major commercial facilities, where Cisco 9800 WLC controllers required careful configuration for web authentication redirection and certificate trust.
The scale and complexity of the authority’s device environment added another layer of challenge. Any new production rollout required alignment across network infrastructure, security, Intune administration, and GPO management teams. Dual deployment paths added complexity: GPO (WSTEP) for domain-joined Windows machines and Intune (SCEP) for cloud-managed devices.
The Solution
Comprehensive implementation sessions with SecureW2 support covered Intune profile configuration, GPO certificate templates, and guest portal setup.
Certificate enrollment followed two paths: WSTEP certificates distributed via Group Policy for domain-joined Windows machines, and SCEP certificates via Intune for cloud-managed devices. Both paths authenticate against Cloud RADIUS with Entra ID as the identity source.
Guest Wi-Fi access mediated by the SecureW2 platform went live across primary buildings, including major commercial facilities. Configuration of Cisco 9800 WLC controllers required extensive troubleshooting — DNS/hostname settings and certificate trust both needed hands-on resolution. The breakthrough came when the team identified a specific IP address configuration on the WLC that immediately resolved the web authentication redirection issue.
The Results
- Migrated from Cisco ISE to SecureW2: eliminating the connectivity support tickets that overwhelmed the help desk.
- Closed a critical vulnerability in the authority’s Wi-Fi authentication model, replacing a legacy access control system that had become a security liability.
- Brought 4,000 devices under certificate-based corporate Wi-Fi across transportation and infrastructure facilities.
- Deployed guest Wi-Fi at major commercial and transportation facilities.
With corporate wireless and guest access live, the authority is positioned to extend certificate-based authentication across additional facilities and device types. The deployment demonstrates that even agencies with complex procurement and multi-team coordination can move from legacy network access to certificate-based authentication with the right champion and channel partner.