Back to Customer Stories
Financial Services / FinTech
1min read
August 2, 2026

FinTech Secures 1,850 Devices With Certificate-Based Wi-Fi During an AD Migration

At a Glance
Industry Financial Services / FinTech
Use Case Dual-MDM certificate deployment (Intune + Kandji), Active Directory migration, certificate lifecycle cleanup
Products Cloud RADIUS, Dynamic PKI
Key Result Expanded SecureW2 deployment to support certificate cleanup and the company’s Active-Directory-to-Okta migration

The Challenge

Switching identity providers is hard enough without worrying about whether 1,850 devices will stay connected to the corporate network.

A home improvement fintech was migrating away from Active Directory (AD) at a time when Microsoft had deprecated certain authentication methods.

Running Intune for Windows and Kandji for macOS meant maintaining two separate Simple Certificate Enrollment Protocol (SCEP) enrollment configurations, each with its own profile structure and troubleshooting requirements.

Over time, device lifecycle events — retirements, re-enrollments, re-images — left behind certificates that no longer corresponded to active devices, leaving the client with more enrolled devices than the company actually managed.

The Solution

The SecureW2 platform addressed the company’s dual mobile device management (MDM) and certificate management requirements and supported future Okta-based device trust initiatives.

Windows and macOS devices receive user-based certificates through Intune and Kandji SCEP profiles, respectively, for authentication against SecureW2 Cloud RADIUS for Wi-Fi access. Okta serves as the identity provider, with certificate attributes tied to verified user identities rather than device records.

The SecureW2 team worked with the company to audit enrolled certificates, identify stale entries from retired or re-imaged devices, and clean up the device inventory, resolving a discrepancy of several hundred devices between the portal count and the actual fleet size.

The SecureW2 platform provides real-time identity lookups during RADIUS authentication, pulling user attributes and device compliance status from Okta to inform network access decisions. This capability is especially valuable as the organization completes its migration away from Active Directory.

The Results

  • 1,850 devices secured: Certificate-based Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) across both Windows (Intune) and macOS (Kandji) secured the company’s device fleet.
  • Stale certificates cleared: Multi-session cleanup resolved the device count discrepancy between the portal and actual fleet.
  • AD migration supported: The SecureW2 certificate and identity infrastructure supported the transition to Okta as the primary trust anchor for network access.

As the Active Directory migration completes, the company will rely entirely on Okta and SecureW2 Cloud RADIUS as the identity and access backbone for its network. This sets the team up to add device compliance checks and conditional access policies as the security posture matures.

Learn More About SecureW2

Explore SecureW2's trust model, dive into our platform and product details or read more success stories.

Why SecureW2

Establish continuous trust with Dynamic PKI and Cloud RADIUS. Enforce access based on live identity, device posture, and risk context.

  • Passwordless authentication that can’t be phished
  • Works with your IdP, MDM, and security stack
  • Real-time policy engine for dynamic access control
Explore the Platform

Get the essentials on the products that power continuous enforcement.

Knowledge Base Articles

Explore practical guidance from engineers and admins deploying SecureW2.

  • Setup and configuration tutorials
  • Integration best practices with IdPs and MDMs
  • Troubleshooting guides for PKI and RADIUS