Back to Customer Stories
K-12 Education
2min read
June 13, 2026

How an Australian K-12 School Updated Their Firewall, While Keeping Network Segmentation Intact

At a Glance
Industry K-12 Education
Use Case BYOD and managed device segmentation, age-based content filtering via VLAN assignment
Products Cloud RADIUS, Dynamic PKI, MultiOS for Device Onboarding
Key Result Reliable certificate-based Wi-Fi across managed devices and BYOD with VLAN-based content filtering by age group

The Challenge

An independent K-12 school in Australia already used SecureW2 for device management, cloud-based RADIUS services and PKI. With hundreds of students and staff, and both personal and managed devices, the client was managing a diverse BYOD environment that required extra care.

The school’s IT team needed to distinguish between managed devices issued by the school and unmanaged BYOD at the point of network authentication, as well as manage Intune and Jamf integrations for the multi-OS environment.

In addition, they needed to assign devices to different VLANs based on whether it was a staff member or a student signing in. With students, they needed to enforce age-appropriate content filtering to allow both young children and teenagers to browse the internet safely. Malware was also a proximate concern given the quantity of user-owned devices coming to campus.

The system was robust, but a move to Cisco Meraki and Umbrella broke the user-to-IP mapping that had previously supported identity-based filtering. The IT team needed to rebuild that mapping through the network authentication layer, using certificate attributes to identify each user and route them to the correct network segment with the correct filtering rules already applied.

The Solution

With SecureW2 support, the client successfully updated their network segmentation system to ensure staff and students stay on separate networks, keeping JoinNow Cloud Radius at the center.

When a device connects, Cloud RADIUS evaluates the certificate and applies a layered policy workflow to isolate each one to the proper network. Managed devices get routed to one VLAN, and BYOD devices get routed to another. Within the BYOD segment, student age groups determine which content filtering rules apply.

The deployment uses JoinNow Connector PKI for managed device enrollment and JoinNow MultiOS for BYOD self-service onboarding. Students and staff authenticate through Entra ID, and the BYOD onboarding flow provisions certificates through a self-service portal that works across all major device operating systems.

As the school prepares for a migration to WPA3, SecureW2 solutions maintain network security and segmentation across the diverse device environment. An integration with Meraki supports transition mode to ensure even older devices maintain network access, even as the device fleet transitions to full WPA3 for gold-standard Wi-Fi security.

The Results

  • Three years of continuous operation with no reported issues since initial deployment
  • BYOD and managed devices separated into distinct VLANs
  • Age-based content filtering enforced through certificate identity and VLAN assignment by student age
  • Self-service BYOD onboarding works across Windows, macOS, iOS, and Android

The school’s network ties every connection to a verified identity. When the WPA3 migration completes, the same certificate infrastructure will support the new encryption standard, preserving three years of accumulated device trust.

Learn More About SecureW2

Explore SecureW2's trust model, dive into our platform and product details or read more success stories.

Why SecureW2

Establish continuous trust with Dynamic PKI and Cloud RADIUS. Enforce access based on live identity, device posture, and risk context.

  • Passwordless authentication that can’t be phished
  • Works with your IdP, MDM, and security stack
  • Real-time policy engine for dynamic access control
Explore the Platform

Get the essentials on the products that power continuous enforcement.

Knowledge Base Articles

Explore practical guidance from engineers and admins deploying SecureW2.

  • Setup and configuration tutorials
  • Integration best practices with IdPs and MDMs
  • Troubleshooting guides for PKI and RADIUS