Enterprise-Grade Certificate Authentication for Managed Devices via Fleet MDM

Fleet MDM manages the devices. SecureW2 issues the certificates. ACME with hardware binding for Apple fleets. SCEP for macOS, Windows, Linux, ChromeOS, iOS, and Android. Cloud RADIUS enforces access at every authentication; no manual revocation required.

Overview

One External CA. Two Enrollment Paths.

Fleet MDM, built on the open-source platform osquery, manages macOS, iOS, iPadOS, Windows, Linux, ChromeOS, and Android devices from a single control plane. SecureW2 integrates as the external certificate authority, automatically handling digital certificates across devices without requiring manual IT intervention.

 

Fleet offers two enrollment methods. For Apple devices, it pushes a .mobileconfig profile via Apple MDM with an ACME payload and HardwareBound: true, generating the private key in the Secure Enclave that never leaves the hardware. For other platforms, Fleet provides SCEP credentials via its built-in SCEP CA, allowing devices to request certificates directly from SecureW2, generating keys on-device.

 

JoinNow Cloud RADIUS enforces network access at authentication, checking Fleet enrollment status. Devices removed from Fleet lose network access on the next connection attempt without manual intervention.

Use Cases
Compliance-Driven Certificate Revocation
Zero-Touch VLAN Segmentation
Video Overview

See the Integration in Action

Want to See More Demos, Click Here
How It Works

Automate Certificate Enrollment via FleetMDM

ACME Enrollment with Apple Device Attestation

Fleet pushes a signed .mobileconfig profile via Apple MDM. The device generates a 384-bit EC private key inside the Apple Secure Enclave and requests a certificate from SecureW2’s ACME API. The key never leaves the hardware, not even during enrollment.

SCEP Enrollment and EAP-TLS Authentication (Cross-Platform)

Fleet distributes SecureW2 SCEP credentials to every device it manages, macOS, Windows, Linux, ChromeOS, iOS, and Android. Devices request certificates directly from JoinNow Dynamic PKI. At authentication, Cloud RADIUS validates the certificate and checks the device’s live Fleet enrollment state before granting network access.

Use Cases

Deployment & Architecture Detail

Compliance-Driven Certificate Revocation

The SecureW2 FleetDM's integration delivers certificate-based authentication for managed device fleets, with no user interaction, shared secrets, or manual provisioning. JoinNow issues certificates automatically through FleetDM's configuration profiles, using Apple Managed Device Attestation to bind credentials to verified Apple hardware via ACME or Dynamic SCEP. Once enrolled, Cloud RADIUS enforces access policy against live FleetDM posture data, revoking access immediately if a device falls out of management or fails a compliance check.

Zero-Touch VLAN Segmentation

FleetDM's device group membership and compliance status determine VLAN assignment during authentication via Cloud RADIUS. No manual VLAN assignment is required; devices are placed in the correct network segment automatically based on their current FleetDM state. A managed, compliant device in the Corporate Devices Smart Group receives full corporate access. A non-compliant device is placed in a restricted VLAN with internet-only access. A device not found in FleetDM is denied access entirely. Because VLAN assignment is evaluated at every authentication, changes to FleetDM group membership take effect at the next connection attempt. No certificate reissuance or profile update is required.

Frequently Asked Questions

Fleet MDM Integration — Common Questions

Should I use ACME or SCEP for my Fleet deployment?

Use ACME for Apple devices (macOS Ventura+, iOS 16+, iPadOS 16+). ACME with HardwareBound: true binds the private key to the device Secure Enclave; the key cannot be exported, copied, or phished. Use SCEP on Windows, Linux, ChromeOS, Android, and older Apple devices. Both paths can coexist in the same Fleet environment using separate configuration profiles and Fleet variable substitution.

What platforms does Fleet MDM support for certificate enrollment?

Fleet MDM supports macOS, iOS, iPadOS, Windows, Linux, ChromeOS, and Android. The ACME enrollment path is available for Apple devices when Apple MDM is enabled in Fleet. The SCEP enrollment path is available for all platforms Fleet manages, configured through Fleet's Certificate Authorities integration.

Does ACME enrollment require Apple MDM to be enabled in Fleet?

Yes. ACME certificate delivery uses Fleet's Apple MDM feature to push the .mobileconfig profile to devices. Without Apple MDM enabled in Fleet (Settings > Integrations > MDM > Turn on Apple MDM), Fleet cannot distribute the ACME payload. SCEP enrollment does not require Apple MDM and works across all Fleet-supported platforms.

Is the certificate private key protected on non-Apple devices using SCEP?

On non-Apple platforms, the SCEP private key is generated on the device and stored in the OS keychain (software storage). The key is never transmitted to SecureW2; only the Certificate Signing Request (CSR) is sent. The certificate is phishing-resistant because the private key is device-bound, but it does not use dedicated hardware security module storage.

How does automatic certificate renewal work with Fleet MDM?

For ACME, add the $FLEET_VAR_CERTIFICATE_RENEWAL_ID variable in the Subject OU field of the .mobileconfig profile. Fleet uses this variable to trigger automatic certificate renewal before expiration without requiring re-enrollment. For SCEP, JoinNow can be configured to issue a renewed certificate before the existing one expires using the same SCEP URL and challenge.

What happens when a device is removed from Fleet?

When a device is unenrolled or removed from Fleet, JoinNow's revocation workflow detects the change and revokes the device's certificate. At the next network authentication attempt, Cloud RADIUS checks the Certificate Revocation List (CRL) or performs a live enrollment check and returns an Access-Reject. No manual administrator action is required; network access is removed automatically.

Is the fleetctl agent required on devices?

Yes. The fleetctl agent must be installed on each device to enroll it in Fleet. The agent is built on osquery and is a prerequisite for Fleet to manage the device and deliver configuration profiles for both ACME and SCEP certificate enrollment.

Does this integration support VLAN segmentation based on Fleet device groups?

Yes. Cloud RADIUS network policies can be configured to evaluate Fleet device group or team membership at authentication time and return different VLAN assignments based on the group. Devices in one team receive corporate VLAN access; devices in another receive restricted access, enforced at every authentication, not just during enrollment.

Ready to Connect SecureW2 with Fleet MDM?

Connect with our integration specialists to implement this solution in your environment and transform your security posture.