The Challenge
A leading digital security company serving thousands of organizations worldwide wanted to improve certificate-based authentication for its 20,000-device network. With a large enterprise network, migrating to a new system proved complicated.
Its previous certificate and RADIUS solution lacked integrations with Splunk and CrowdStrike — tools the company relied on for security visibility. The team needed a PKI solution that could ingest real-time risk signals from their identity platform and feed authentication data into their security stack.
The company’s own security policies created integration requirements that few vendors could meet. For example API tokens with Super Admin access were prohibited, and instead the team required OAuth-based, least-privilege connections for any third-party integration. The production environment also had limited options for real-time certificate revocation when employees were terminated or suspended.
The device fleet spanned three distinct enrollment paths: Jamf Pro for Mac (the majority), Microsoft Intune for Windows, and a BYOD workflow for personal iOS devices. Each path required its own certificate template, enrollment policy, and RADIUS configuration. Adding difficulty, the previous PKI vendor had an existing external CA connection in Jamf.
The Solution
The company ran a full proof of concept over a 12-month period, comparing SecureW2 against the incumbent solution. A staff network engineer on the corporate platform engineering team led the proof of concept, running tests across all three enrollment paths.
The deployment covered three enrollment paths: dynamic SCEP for Mac through Jamf Pro, WSTEP and SCEP-based enrollment for Windows through Intune, and self-service certificate enrollment for BYOD iOS devices with identity provider integration. The company’s own identity platform was configured for SAML-based login to the SecureW2 management console.
For auto-revocation, the team explored Workflows with a custom connector as an alternative to event hooks, since the production environment had maxed out its 25-hook capacity.
The Results
- Move to Cloud RADIUS for certificate-based authentication after a rigorous technical evaluation
- 20,000 devices across three OS platforms under certificate-based authentication
- Opportunity to drive product innovation and joint go-to-market opportunities through partnership with leader in digital security