SecureW2 × Palo Alto Cortex Integration SecureW2 turns Palo Alto Cortex risk signals into real-time access control. Every device’s risk changes constantly. SecureW2 ingests Palo Alto’s endpoint threat signals and acts on them: posture-gated certificate issuance blocks compromised devices at enrollment, and webhook-driven revocation kills access the moment Cortex detects a threat, no manual step required.
Overview
Every device carries some level of risk, but that risk changes constantly. By ingesting Palo Alto’s risk signals, SecureW2 ensures network access reflects a device’s current security posture not just its state at enrollment. Certificates are only valid as long as the device remains trustworthy.
The integration connects SecureW2’s Dynamic PKI and Cloud RADIUS policy engine directly with Palo Alto’s endpoint threat intelligence. SecureW2 queries Palo Alto for a device’s “Overall Assessment” risk score before issuing any certificate, and receives webhook notifications the moment device status changes after enrollment. When Palo Alto detects a threat, compromise, or compliance violation, SecureW2 revokes the certificate immediately and Cloud RADIUS blocks the device at the next connection automatically, without human intervention. Setup takes approximately 30 minutes.
How It Works
Before issuing a certificate, SecureW2 Dynamic PKI queries Palo Alto for the device’s “Overall Assessment” risk score. Healthy devices receive a certificate. Devices flagged as compromised or non-compliant are denied they never gain network credentials in the first place.
After enrollment, Palo Alto continues monitoring the device. When status changes, Cortex sends a webhook to SecureW2, which revokes the certificate immediately. Cloud RADIUS blocks the device at its next connection attempt detection to enforcement, automated.
Personal devices go through the same JoinNow onboarding flow and Palo Alto posture check as corporate-managed endpoints, no MDM agent required for certificate issuance. Before a BYOD device receives a certificate, SecureW2 queries Palo Alto for its current "Overall Assessment" risk score. Devices that fail the posture threshold are denied credentials, regardless of whether they are corporate or personal.
SecureW2 supports separate certificate templates for BYOD populations, enabling IT to assign personal devices to a restricted VLAN or access tier distinct from fully managed endpoints. If a personal device's posture degrades after enrollment, the same webhook-driven revocation applies, Palo Alto signals the status change, SecureW2 revokes the certificate, and Cloud RADIUS blocks the device at its next connection attempt without any IT intervention.
JoinNow Cloud RADIUS enforces certificate-based network access and evaluates device posture at every authentication. When Palo Alto signals that a device's risk posture has changed, Cloud RADIUS incorporates that signal into its policy decisions at the next connection attempt.
A device flagged by Palo Alto as compromised, even one that recently passed authentication, is denied access on its next attempt. Because the decision is made live at every authentication, access always reflects the device's current state rather than the state captured at enrollment. Cloud RADIUS supports EAP-TLS and 802.1X, enabling certificate-based Wi-Fi and network access across the fleet.
Frequently Asked Questions
This integration connects SecureW2’s Dynamic PKI and policy engine with Palo Alto's risk signals. It turns device risk assessments into automated certificate issuance, updates, or revocations—ensuring only compliant, trusted devices retain access to your network and applications.
This integration helps automate your security processes. Instead of relying on manual actions, it uses real-time data to automatically manage device access, which helps prevent breaches and simplifies your IT workload
SecureW2 uses the "Overall Assessment" value, which is considered the device's risk score. It can also use other attributes like the device's serial number, operating system, and a unique agent ID.
The integration uses webhooks to automatically update access policies. This means that if a device's risk score changes or a user's status is altered in Palo Alto, SecureW2 is notified instantly and can automatically apply the correct network policy, ensuring security is always up to date.
Yes, this integration can also support BYOD (Bring Your Own Device). It allows for a simplified and secure onboarding process for personal devices, ensuring they are automatically validated for compliance and risk before being granted network access, without requiring an agent.
Connect with our integration specialists to implement this solution in your environment and transform your security posture.