Back to Customer Stories
Technology / Digital Platform Security
2min read
August 29, 2026

How a Global Tech Firm Partnered with SecureW2 to Ditch its Legacy Infrastructure and Scale Securely

At a Glance
Industry Technology / Digital Platform Security
Use Case Corporate Wi-Fi 802.1X, managed device enrollment via Intune and Jamf, BYOD onboarding, guest Wi-Fi portal, dynamic VLAN segmentation
Products N/A
Key Result Replaced Cisco ISE for certificate-based Wi-Fi across global offices, eliminating the need to stand up on-premises infrastructure at new locations

The Challenge

A global digital platform security company with offices on three continents had built its corporate Wi-Fi authentication on Cisco ISE. The infrastructure worked, but it carried a cost: operational complexity that grew with every new office. When the company prepared to open a new location in Australia, the team faced a familiar question — stand up another ISE deployment, or find something better.

The answer was neither quick nor simple. The existing Cisco ISE deployment made EAP-TLS cumbersome to manage. The security team needed a solution that integrated with Entra ID for identity and Intune and Jamf for device management.

The device fleet included Windows machines managed through Intune and Macs managed through Jamf. BYOD devices from employees needed a separate onboarding workflow with Azure AD authentication. And visitors to each office needed guest Wi-Fi access through a sponsor-managed portal. Each of these populations required its own enrollment policy, certificate configuration, and RADIUS treatment.

The Solution

The company deployed the SecureW2 JoinNow platform as a full replacement for Cisco ISE across its certificate-based Wi-Fi infrastructure. The implementation covered 1,500+ devices in the initial phase, with separate enrollment policies for each device population.

Windows devices enrolled through Intune. Mac devices enrolled through Jamf with their own certificate template and enrollment policy. The team configured Azure AD group-based policy differentiation to route devices to the correct enrollment workflow automatically — preventing the overlap that occurs when both platforms match on the same conditions.

BYOD enrollment used SAML authentication against Azure AD, allowing employees to self-provision certificates on personal devices through a browser-based workflow. JoinNow Cloud RADIUS handled all authentication requests.

For guest access, the team configured a sponsor-based guest Wi-Fi portal — replacing ad-hoc guest network arrangements with a structured workflow tied to the same RADIUS infrastructure.

The deployment eliminated the need to build on-premises ISE infrastructure at the new Australia office. Cloud RADIUS handled authentication for all locations through a single management plane.

The Results

  • Cisco ISE replaced for certificate-based Wi-Fi authentication across global offices
  • 1,500 devices under certificate-based authentication in Phase I, with expansion planned
  • Three enrollment paths — Intune (Windows), Jamf (Mac), and BYOD — each with dedicated policies and certificate templates
  • No on-premises infrastructure required at the new Australia office — Cloud RADIUS handled authentication from day one
  • Guest Wi-Fi portal deployed with sponsor-based workflows

A company that builds security products for other organizations chose to scale using cloud-native PKI and RADIUS instead of expanding its existing Cisco ISE deployment. The decision came down to integration depth, operational simplicity, and the ability to extend secure Wi-Fi to new locations without shipping hardware.

Learn More About SecureW2

Explore SecureW2's trust model, dive into our platform and product details or read more success stories.

Why SecureW2

Establish continuous trust with Dynamic PKI and Cloud RADIUS. Enforce access based on live identity, device posture, and risk context.

  • Passwordless authentication that can’t be phished
  • Works with your IdP, MDM, and security stack
  • Real-time policy engine for dynamic access control
Explore the Platform

Get the essentials on the products that power continuous enforcement.

Knowledge Base Articles

Explore practical guidance from engineers and admins deploying SecureW2.

  • Setup and configuration tutorials
  • Integration best practices with IdPs and MDMs
  • Troubleshooting guides for PKI and RADIUS