SecureW2 Automates Certificate Issuance for Jamf-Managed Apple Devices

SecureW2 auto-enrolls and manages certificates for network access control by leveraging Jamf’s robust device management capabilities. The combined power of the platforms enforces real-time network policy based on device attributes and user context, enabling granular network segmentation and dynamic VLAN assignment.

Overview

Secure Apple Fleets with Hardware-Attested Certificates

The SecureW2 Jamf integration delivers certificate-based authentication for Apple fleets, no user interaction, shared secrets, or manual provisioning. JoinNow issues certificates automatically through Jamf configuration profiles, using Apple Managed Device Attestation to bind credentials to verified Apple hardware via ACME or Dynamic SCEP. Once enrolled, Cloud RADIUS enforces access policy against live Jamf posture data, revoking access immediately if a device falls out of management or fails a compliance check.

Use Cases
Compliance-Driven Certificate Revocation
Zero-Touch VLAN Segmentation
Video Overview

See the Integration in Action

Want to See More Demos, Click Here
How It Works

Two Enrollment Paths. One Compliance-Aware Lifecycle.

ACME Enrollment with Apple Managed Device Attestation

Before SecureW2 issues a certificate, the device must prove it’s genuine Apple hardware with a Secure Enclave-bound private key through Apple’s attestation infrastructure, not Jamf or SecureW2 assertions. Only devices that pass cryptographic attestation and Jamf identity validation receive a certificate. SecureW2’s ACME API Gateway coordinates attestation validation by receiving cryptographic proof from Apple’s servers and verifying it before authorizing Dynamic PKI to sign the certificate request.

Dynamic SCEP Enrollment Flow

Dynamic SCEP eliminates the static shared secret vulnerability. Each device receives a unique challenge tied to its identity at enrollment, valid for a single use. Validation issues a certificate from Dynamic PKI, delivered to the device’s keychain or TPM via the SCEP profile, enabling passwordless EAP-TLS 802.1X authentication without user action.

Use Cases

Deployment & Architecture Detail

Compliance-Driven Certificate Revocation

The SecureW2 Jamf integration delivers certificate-based authentication for Apple fleets, no user interaction, shared secrets, or manual provisioning. JoinNow issues certificates automatically through Jamf configuration profiles, using Apple Managed Device Attestation to bind credentials to verified Apple hardware via ACME or Dynamic SCEP. Once enrolled, Cloud RADIUS enforces access policy against live Jamf posture data, revoking access immediately if a device falls out of management or fails a compliance check.

Zero-Touch VLAN Segmentation

Jamf device group membership and compliance status determine VLAN assignment during authentication via Cloud RADIUS. No manual VLAN assignment is required; devices are placed in the correct network segment automatically based on their current Jamf state. A managed, compliant device in the Corporate Devices Smart Group receives full corporate access. A non-compliant device is placed in a restricted VLAN with internet-only access. A device not found in Jamf is denied access entirely. Because VLAN assignment is evaluated at every authentication, changes to Jamf group membership take effect at the next connection attempt. No certificate reissuance or profile update is required.

Frequently Asked Questions

Jamf Integration — Common Questions

What is the difference between ACME and Dynamic SCEP, and when should I use each?

ACME is the preferred protocol for Apple devices running iOS 16+, iPadOS 16+, macOS, and tvOS. It integrates with Apple Managed Device Attestation to cryptographically prove the device is genuine Apple hardware before SecureW2 issues a certificate. Dynamic SCEP is the fallback for devices that do not support ACME or for mixed-OS environments. Both eliminate the static shared secret vulnerability. If your fleet is exclusively Apple on supported OS versions, use ACME. If you have older devices or non-Apple devices in the same Jamf environment, configure Dynamic SCEP for those devices.

What does Apple Managed Device Attestation actually prove?

Apple MDA proves four things: the device is genuine Apple hardware (not a VM or a spoofed device), the device serial number matches the hardware, the OS has not been tampered with since installation, and the certificate private key is stored in the device's Secure Enclave, meaning it is hardware-bound and cannot be exported. These are cryptographic guarantees from Apple's attestation infrastructure, not assertions from Jamf or SecureW2.

Does this integration work for iOS and iPadOS devices, not just Macs?

Yes. ACME enrollment with Apple MDA is supported on macOS, iOS 16+, iPadOS 16+, and tvOS. Configuration profiles and ACME payloads are pushed through Jamf Pro the same way for all Apple platforms. The enrollment flow and attestation requirements are identical across device types.

What happens when a device is removed from Jamf management?

When a device is unenrolled or wiped from Jamf, SecureW2's auto-revocation process detects that the device is no longer in its managed Smart Group or Static Group during the next revocation evaluation. The device's certificate is revoked automatically. At the next network authentication attempt, Cloud RADIUS checks the certificate against the CRL and denies access. No manual administrator action required.

Can certificates be issued to devices enrolled in Jamf but not compliant at enrollment time?

By default, no. The enrollment policy in JoinNow checks Jamf compliance status as a condition for certificate issuance. If the device is non-compliant, the Policy Engine denies the certificate request. Administrators can configure a separate enrollment policy that issues restricted certificates to non-compliant devices, for example, a certificate that grants access only to a remediation VLAN, but this is an explicit policy decision, not the default behavior.

What Jamf API permissions are required for this integration?

SecureW2 requires a Jamf Read-Only API user. This account needs permission to query device records, retrieve device group membership (Smart Groups and Static Groups), and read compliance status. No write permissions are required. The API credentials are entered in JoinNow when configuring the Jamf Identity Lookup Provider and auto-revocation settings.

How does certificate renewal work for managed Apple devices?

Certificate renewal is handled through the same ACME or Dynamic SCEP enrollment flow. JoinNow can be configured to issue new certificates before expiration using automatic renewal policies. For ACME, the device re-runs attestation as part of renewal, refreshing the hardware identity check with each new certificate. For Dynamic SCEP, Jamf pushes a new SCEP challenge via webhook and the device re-enrolls. In both cases, renewal is transparent to the end user.

Is user interaction required during enrollment?

No. Enrollment is zero-touch. Jamf pushes the configuration profile — either the ACME .mobileconfig or the SCEP profile — to managed devices automatically. The device initiates the ACME or SCEP flow, contacts SecureW2, completes attestation and identity validation, and receives a certificate without the user seeing a prompt or clicking anything. User interaction is only required if the enrollment flow encounters an error that requires remediation.

What happens if a device's compliance status changes between certificate issuance and authentication?

SecureW2 handles this through two mechanisms. First, the Jamf Identity Lookup Provider can be configured to run at RADIUS authentication time, if compliance status has changed, Cloud RADIUS detects this and applies the appropriate policy. Second, the auto-revocation workflow runs on a scheduled basis and revokes certificates for devices that have fallen out of Jamf compliance, so the next authentication attempt will fail CRL validation regardless of the RADIUS lookup result.

Does this integration support Jamf School, or only Jamf Pro?

Absolutely. SecureW2's gateway APIs are designed to integrate with the entire Jamf ecosystem, providing the same level of automated certificate deployment and lifecycle management regardless of which Jamf version you use.

Ready to Connect SecureW2 to Jamf?

Connect with our integration specialists to implement this solution in your environment and transform your security posture.