Replace NDES and static SCEP secrets with JoinNow CloudConnector, a cloud-based SCEP gateway that integrates with SCCM Certificate Registration Point without replacing your infrastructure. Certificates are stored in the Windows TPM and validated by Cloud RADIUS against live Entra ID or Active Directory state at every connection, supporting hybrid-joined fleets and SCCM co-management environments.
Overview
SecureW2 integrates with Microsoft Endpoint Configuration Manager (SCCM/MECM) to provide certificate-based authentication for Windows enterprise devices without static shared secrets, on-premises NDES infrastructure, or manual provisioning. JoinNow CloudConnector replaces the Network Device Enrollment Service (NDES) as a cloud-based SCEP gateway, allowing SCCM-managed Windows devices to receive certificates from JoinNow Dynamic PKI through the standard SCCM Certificate Registration Point workflow. Certificates are stored in the Windows TPM using the TPM Key Storage Provider, binding each certificate to the hardware it was issued to.
JoinNow Cloud RADIUS enforces access policy at authentication time using real-time identity lookups against Active Directory or Microsoft Entra ID. This integration is designed for Windows enterprise environments, including hybrid-joined fleets and organizations using SCCM co-management with Microsoft Intune. SCCM manages device enrollment and certificate profile distribution; only the SCEP endpoint URL changes from NDES to CloudConnector.
JoinNow CloudConnector replaces NDES as the SCEP gateway while preserving the SCCM Certificate Registration Point workflow. The CRP forwards the device’s SCEP request to CloudConnector, which validates the device against Active Directory or Entra ID before authorizing certificate issuance. The issued certificate is stored in the Windows TPM via the TPM Key Storage Provider, and the private key is generated and never exported.
Cloud RADIUS validates the TPM-bound certificate and queries Entra ID or Active Directory for live identity and compliance state. At each connection attempt, the EAP-TLS handshake triggers a real-time directory lookup. If the device’s account is disabled or removed since the certificate’s issuance, access is denied immediately. Cloud RADIUS returns a RADIUS Accept with VLAN assignment for compliant devices, or a Reject for disabled, unenrolled, or non-compliant ones.
WSTEP (WS-Trust Enrollment Protocol) is a Windows-native certificate enrollment protocol that uses WS-Trust for authentication and authorization. Unlike SCEP, which requires a per-device challenge, domain-joined Windows devices authenticate enrollment requests using Kerberos machine credentials, establishing trust through domain membership. SecureW2 supports WSTEP enrollment via CloudConnector, enabling SCCM-managed devices to request certificates through the WS-Trust path without requiring a SCEP profile or challenge URL.
WSTEP is ideal for environments with restricted SCEP traffic, where Kerberos is preferred for internal services, or where organizations have Windows Certificate Enrollment Policy (CEP) and Certificate Enrollment Service (CES) infrastructure. CloudConnector replaces the on-premises CES endpoint, eliminating the need for internal CES servers while preserving the Kerberos-authenticated enrollment workflow familiar to SCCM administrators.
SCCM distributes enrollment configuration to managed devices through standard Configuration Items. The device initiates the WSTEP request using its machine credentials, the Policy Engine validates the machine account against Active Directory, and Dynamic PKI issues the certificate. The enrolled certificate is stored in the Windows machine certificate store and, optionally, generated using the TPM Key Storage Provider for hardware binding.
Organizations transitioning from SCCM-only to Intune co-management typically run both platforms simultaneously. SecureW2 supports both without certificate migration. SCCM devices receive certificates via CloudConnector-based Dynamic SCEP, while Intune devices transition to Intune SCEP with the same SecureW2 CA.
Both enrollment paths issue certificates from the same SecureW2 CA hierarchy, so SCCM and Intune devices authenticate on the same Wi-Fi network under the same Cloud RADIUS policy. There’s no split RADIUS configuration, separate certificate authority, or network disruption during migration.
IT teams can migrate at their own pace. The certificate infrastructure remains stable, and Cloud RADIUS enforces the same access policy regardless of the device’s management path. No coordination with the network team is required at each migration milestone.
Frequently Asked Questions
Connect with our integration specialists to implement this solution in your environment and transform your security posture.