Back to Customer Stories
Quick-Service Restaurant / Retail
2min read
July 15, 2026

How a Restaurant Group Migrated 22,000+ Devices from PSK to Certificate Auth Across 800+ Locations

At a Glance
Industry Quick-Service Restaurant / Retail
Use Case IoT device authentication, PSK-to-certificate migration, REST API enrollment across 800+ locations
Products Cloud RADIUS, Dynamic PKI
Key Result Scaled from 4,000 to 22,100+ devices under certificate-based management in four years — with a first-of-its-kind REST API integration for non-standard tablets

The Challenge

During a routine compliance review, a restaurant group discovered that three payment terminals at drive-in locations had gone haywire, with one device autonomously issuing itself 5,500 certificates. Across the three terminals, the total exceeded 16,000 rogue certificates — blowing past license counts and creating a compliance nightmare.

The company had relied on pre-shared keys to authenticate restaurant devices to Wi-Fi. PSK credentials, once shared, offer no device-level visibility or revocation capability. At hundreds of locations spanning corporate offices, drive-in restaurants, and casual dining brands, that risk multiplied. To remedy the security gap, the company mandated that all restaurant devices — including Android tabletop tablets at casual dining locations — authenticate via EAP-TLS certificates instead.

Those Android tablets presented a unique problem. They had no traditional MDM integration and no SCEP support, meaning standard certificate enrollment paths did not apply. The company needed a way to push certificates to thousands of tablets through a custom cloud-based management system.

The company had previously used a different certificate provider but did not want on-premises RADIUS. A cloud-native PKI and RADIUS bundle that could scale to 50,000+ devices across multiple brands — and support non-standard enrollment for devices outside traditional MDM — narrowed the field to one vendor.

The Solution

The deployment with SecureW2 unfolded in three phases over four years, evolving from a standard corporate rollout into a multi-brand, cross-environment certificate-based authentication program.

In the first phase, the company deployed JoinNow Dynamic PKI and JoinNow Cloud RADIUS to support corporate devices, including Windows laptops and iOS devices managed through Workspace ONE. Certificate enrollment was handled through SCEP, with EAP-TLS used to authenticate devices to Cloud RADIUS over WPA2-Enterprise.

This initial rollout established the foundation for certificate-based authentication at scale, growing from 4,000 to approximately 13,000 devices.

The second phase expanded the deployment into drive-in and restaurant environments, bringing payment terminals and additional store devices into scope. During a compliance audit, 16,000 rogue certificates tied to payment terminals were identified and revoked, prompting a 9,000-device true-up that brought the environment to approximately 21,250 licensed devices. At this stage, the company operated separate SecureW2 tenants for corporate and restaurant brands, each configured with distinct certificate policies and enrollment settings.

The third phase focused on extending certificate-based authentication to a fleet of Android tablets used across casual dining locations spanning 400+ sites. Because the tablet vendor’s cloud-based management platform did not support SCEP, the team implemented a REST API-based certificate enrollment path for them. Through this approach, an orchestrator requests certificates via the REST API on behalf of each device, which initially connects to a guest network before receiving and installing the certificate through the management platform. This enables EAP-TLS authentication without relying on traditional MDM-based enrollment.

The infrastructure now supports a path toward supporting enrollment and management for 50,000–70,000 devices across brands.

The Results

  • Continual certificate growth: The company scaled from 4,000 to 22,150+ licensed devices over four years.
  • PSK eliminated: EAP-TLS certificate-based authentication replaced PSK across corporate and restaurant device fleets.
  • 16,000 phantom certificates identified and revoked: Automated phantom certificates tied to rogue payment terminals were discovered and revoked from the system.
  • First-of-its-kind REST API certificate enrollment path built: SecureW2 built a solution to support certificate enrollment for non-standard Android tablets.
  • Expanding toward 50,000-70,000 total devices across all brands: Growth continues, supported by an OEM/security-module relationship with tablet manufacturers in development.

With the REST API path in production, the company is exploring an OEM relationship with the tablet manufacturer to extend certificate-based authentication to other restaurant brands on the same platform. What started as a corporate Wi-Fi project now shapes how an entire category of restaurant devices connects to the network.

Learn More About SecureW2

Explore SecureW2's trust model, dive into our platform and product details or read more success stories.

Why SecureW2

Establish continuous trust with Dynamic PKI and Cloud RADIUS. Enforce access based on live identity, device posture, and risk context.

  • Passwordless authentication that can’t be phished
  • Works with your IdP, MDM, and security stack
  • Real-time policy engine for dynamic access control
Explore the Platform

Get the essentials on the products that power continuous enforcement.

Knowledge Base Articles

Explore practical guidance from engineers and admins deploying SecureW2.

  • Setup and configuration tutorials
  • Integration best practices with IdPs and MDMs
  • Troubleshooting guides for PKI and RADIUS