SecureW2 auto-enrolls and manages certificates for network access control by leveraging MobileIron’s robust device management capabilities. The combined power of the platforms enables real-time network policy enforcement based on device attributes and user context, allowing for granular network segmentation and dynamic VLAN assignment.
Overview
SecureW2 integrates with MobileIron, now part of Ivanti’s portfolio as Ivanti Neurons for MDM, to deliver automated certificate enrollment across iOS, Android, macOS, and Windows device fleets at enterprise scale. Certificates are issued through MobileIron configuration profiles using Dynamic SCEP on all supported platforms, with no static shared secret, no manual provisioning, and no user interaction required. JoinNow Dynamic PKI validates each device’s management status in MobileIron before issuing a certificate, ensuring that only enrolled, recognized devices can obtain credentials.
The integration is designed for environments where network segmentation, compliance enforcement, and certificate lifecycle management must operate at scale across thousands of devices spanning multiple platforms. JoinNow Cloud RADIUS enforces access policy at authentication time by checking the authenticating device’s current compliance state in MobileIron, not against a cached copy of directory data. Devices that fall out of compliance can have their certificates automatically revoked, ending network access without waiting for certificate expiration or any administrator intervention.
MobileIron delivers a SCEP profile with a unique per-device challenge across iOS, Android, macOS, and Windows. When the device submits its certificate request, MobileIron triggers a SCEPChallenge webhook to CloudConnector, which validates the device’s management status and generates a one-time challenge tied to that specific device. The Policy Engine verifies the challenge and issues a certificate from Dynamic PKI, the challenge cannot be reused or transferred to another device.
At each connection attempt, the device presents its certificate to the access point or VPN gateway, which forwards the EAP-TLS request to Cloud RADIUS for validation. Cloud RADIUS verifies the certificate and performs a live MobileIron compliance lookup, returning an Access-Accept with the appropriate VLAN assignment if the device is enrolled and compliant, or an Access-Reject if it is not. Because the compliance check runs at authentication time rather than enrollment time, a device that falls out of compliance after receiving its certificate is caught at the next connection attempt without any administrator action.
JoinNow Cloud RADIUS performs a real-time lookup against MobileIron at authentication time, so the access decision is based on the device's current compliance state rather than the state at the time the certificate was issued. A MobileIron Identity Lookup Provider is configured in JoinNow with read-only API credentials that allow querying device records, group membership, and compliance status. When a device presents a certificate for EAP-TLS authentication, Cloud RADIUS uses the certificate's Subject and SAN fields to identify the device, then queries MobileIron for its current compliance status and group membership. The Policy Engine evaluates those attributes against the configured network policy.
A managed, compliant device in the approved group receives an Access-Accept with a corporate VLAN assignment. A device that has fallen out of compliance receives either a restricted VLAN assignment or an Access-Reject, depending on policy configuration. A device not found in MobileIron is rejected outright. Because the lookup runs on every authentication attempt, a device that becomes non-compliant between certificate issuance and the next network connection is caught at the RADIUS stage, even if its certificate is still within its validity period.
MobileIron device group membership and compliance status drive VLAN assignment at authentication time via Cloud RADIUS, placing devices in the appropriate network segment based on their current MobileIron state without manual VLAN configuration. RADIUS access policies in JoinNow read MobileIron attributes at authentication time: the MobileIron Identity Lookup Provider retrieves the authenticating device's label assignments, group membership, and compliance status, and Cloud RADIUS evaluates those attributes against policy rules to return an Access-Accept with the appropriate VLAN tag and access level.
For example, a managed, compliant corporate device is assigned VLAN 10 for full corporate access; a device flagged as non-compliant is assigned VLAN 30 for restricted internet-only access; a device in a contractor-designated MobileIron Space is assigned VLAN 50; and a device not enrolled in MobileIron receives an Access-Reject. VLAN assignment is re-evaluated at every authentication, so a device moved to a non-compliant group will receive restricted access at its next Wi-Fi or VPN authentication, with no certificate reissuance or profile update required.
Frequently Asked Questions
Connect with our integration specialists to implement this solution in your environment and transform your security posture.