Back to Customer Stories
Higher Education
1min read
June 5, 2026

Scaling With the Campus: From BYOD to Campus-Wide Zero Trust

At a Glance
Industry Higher Education
Use Case BYOD enrollment, guest/IoT network authentication, managed device gateway, campus-wide PKI
Products Cloud RADIUS, Dynamic PKI, JoinNow Platform, MultiOS for Device Onboarding
Key Result chieved campus-wide certificate-based security across all device types — BYOD, guest, IoT, and managed — through a phased deployment that scaled year over year without disrupting existing infrastructure.

The Challenge

A university wanted to improve wireless security and reduce help desk tickets, while providing seamless network access to students and faculty. Administrators wanted to create a self-service BYOD enrollment system. The school also wanted to provide network access to guest devices, IoT sensors, and department-owned equipment, all with carefully calibrated levels of trust.

There were some built-in challenges. Domain-joined machines required a different enrollment path than personal devices. And as the university’s digital footprint grew, the IT team needed a platform that could scale with them — adding capabilities year over year without ripping out what already worked.

The Solution

The university started by deploying JoinNow MultiOS for self-service BYOD enrollment and JoinNow PKI for certificate management. Students and staff enrolled their personal devices through a guided workflow that issued digital certificates tied to their university identity.

Following the successful BYOD deployment, the university expanded its JoinNow deployment to cover the growing population of devices that did not belong to any individual user but still needed controlled network access — like guest devices and IoT tools. Later, JoinNow was extended to handle domain-joined machines through a separate enrollment path, issuing certificates to university-owned equipment, managed by IT.

Recently, the university consolidated its certificate management into a single, centralized architecture with continuous trust monitoring capabilities. The upgrade brought the ability to enforce compliance checks throughout the certificate lifecycle, not just at the moment of issuance.

Each expansion built on the infrastructure already in place. The channel partner managing the relationship facilitated procurement through annual renewals, keeping the upgrade path smooth and predictable for the university’s budget cycle.

The Results

  • BYOD, guest, IoT, and managed devices all secured under a single certificate-based platform
  • Reduced IT burden through self-service BYOD enrollment, empowering students and staff to onboard their own devices without help desk assistance
  • Expanded security coverage incrementally over multiple years, with each phase building on existing infrastructure

The deployment illustrates what a phased approach to certificate-based network security looks like in practice. Starting with BYOD and expanding into guest authentication, managed devices, and continuous trust enforcement, the university built a comprehensive security posture one layer at a time.

Learn More About SecureW2

Explore SecureW2's trust model, dive into our platform and product details or read more success stories.

Why SecureW2

Establish continuous trust with Dynamic PKI and Cloud RADIUS. Enforce access based on live identity, device posture, and risk context.

  • Passwordless authentication that can’t be phished
  • Works with your IdP, MDM, and security stack
  • Real-time policy engine for dynamic access control
Explore the Platform

Get the essentials on the products that power continuous enforcement.

Knowledge Base Articles

Explore practical guidance from engineers and admins deploying SecureW2.

  • Setup and configuration tutorials
  • Integration best practices with IdPs and MDMs
  • Troubleshooting guides for PKI and RADIUS