Want to learn the best practice for configuring Chromebooks with 802.1X authentication?

Sign up for a Webinar!
Case Studies

School District Secures Wi-Fi With Cloud RADIUS

BYOD
Google
K-12
MDM
Meraki
PKI
Case Study Hero BG

Deployment Timeline

This school district has over 3,000 students across three elementary schools, a middle school, and a high school. They were looking to transition to a certificate-backed EAP-TLS network, while still leveraging their current network environment.

Originally, they attempted to utilize their already existing FreeRADIUS to authenticate certificates but found the process too difficult. They considered hiring a FreeRADIUS expert to help them transition but found this to be too expensive a solution.

They contacted SecureW2 in June 2021 and were fully equipped with an EAP-TLS network ready for students in the Fall.

Challenges

The school was using FreeRADIUS with EAP-PEAP but were having trouble with students forgetting and sharing their password.

Quote Left Icon
You really can’t rely on student discretion when it comes to keeping passwords secure. We needed increased network visibility to protect the integrity of our Wi-Fi, but using FreeRADIUS with our on-premise directory was expensive.
AAMIR, NETWORK INFRASTRUCTURE SPECIALIST

Their managed devices were mostly Chromebooks so they originally considered using G-Suite with FreeRADIUS with a custom PKI for EAP-TLS but found that they would have to purchase the most expensive Google license to work with their AD-CS and on-premise directory. The school also needed a way for students with a varying range of computer literacy to be able to self-enroll their BYOD devices with certificates, while also easily pushing certificates onto their managed devices.

Quote Left Icon
It was a relief that we didn’t need to buy all new infrastructure to support passwordless authentication. SecureW2’s support team helped us integrate our controllers, Ubiquiti access points, and servers to leverage our existing identities for certificate issuance.
AAMIR, NETWORK INFRASTRUCTURE SPECIALIST

Solution

After several internal meetings and a trial period, the school district decided to go with SecureW2’s PKI service to integrate because it would integrate seamlessly with their Google and AD environment.

Quote Left Icon
We needed a solution that was just plug and play with our current network infrastructure. That’s exactly what we got with SecureW2.
AAMIR, NETWORK INFRASTRUCTURE SPECIALIST

SecureW2 onboarding software communicates with G-Suite, granting trust to the end-user and issuing a certificate. Certificates offer the best form of network security due to their high-level encryption that’s nearly impossible to crack. The client can then present the certificate to the RADIUS server to be authenticated and authorized for secure network access.

Using SecureW2, students bringing their own devices can easily issue custom certificates for themselves through JoinNow to access the school’s network. The best part? These certificates are cryptographically linked to the user, so there is no risk of sharing certificates and you can rest assured that users are who they say they are.

Evaluating Success

SecureW2 an industry-leading Cloud PKI made enrolling the school’s Chromebooks and other devices for certificate-based authentication a breeze. Because our software requires no prior knowledge of PKIs and is easily integrated into their existing network environment, the IT team was able to get their network set up before the next school year began.

With a fully functional management portal, the IT department can easily manage and revoke certificates and stay aware of the comings and goings of their network.

Quote Left Icon
Having full visibility of network activity has made our job so much easier.
AAMIR, NETWORK INFRASTRUCTURE SPECIALIST