Deploy X.509 certificates to Apple devices via SimpleMDM Assignment Groups. Use ACME with Apple hardware attestation for iOS 16+ and macOS Ventura or later, and Dynamic SCEP for older OS versions. Cloud RADIUS enforces live SimpleMDM enrollment status at every connection, ensuring access decisions reflect your current device inventory.
Overview
SecureW2 integrates with SimpleMDM to automate certificate enrollment for Apple device fleets without shared secrets, manual provisioning, or enterprise-scale MDM infrastructure. Certificates are issued through SimpleMDM configuration profiles using SCEP or ACME payloads and pushed to devices via SimpleMDM Assignment Groups, enabling smaller IT teams to access the same certificate-based authentication capabilities as large enterprises. JoinNow Dynamic PKI handles certificate issuance and lifecycle management, while JoinNow Cloud RADIUS enforces access policy at authentication time using SimpleMDM’s identity and device data.
The integration supports two enrollment protocols: ACME and Dynamic SCEP. ACME is preferred for Apple devices running iOS 16+ or macOS Ventura and later, using Apple device attestation to verify genuine hardware before issuing a certificate. Dynamic SCEP replaces the traditional static shared secret with a unique per-device challenge for devices that cannot use ACME, eliminating the primary vulnerability in standard SCEP deployments. Both paths are available through SimpleMDM’s standard configuration profile workflow.
SecureW2 validates Apple hardware attestation and SimpleMDM device enrollment as synchronized gates before issuing a certificate. Only devices passing both checks receive a certificate. Its private key is generated in the device’s Secure Enclave and cannot be exported, copied, or used elsewhere.
SimpleMDM uses its Assignment Group system to push a unique SCEP profile with a challenge for each device. No static shared secret is used; each challenge is generated and validated before issuance. Once validated, the certificate is automatically delivered to the device keychain, ready for 802.1X EAP-TLS Wi-Fi and VPN authentication without user action.
SimpleMDM’s Assignment Groups control app, profile, and configuration deployment to devices. SecureW2 extends this model to network access, mapping Assignment Groups to network segments at authentication. Devices in the “Executive” group receive different access than those in the “General Staff” or “Contractors” groups.
Cloud RADIUS reads Assignment Group membership through SimpleMDM’s Identity Lookup at authentication, mapping it to RADIUS policy attributes, including VLAN assignments. Changes in Assignment Groups take effect at the next authentication without certificate reissuance, profile updates, or manual RADIUS policy changes.
This model suits Apple-first SMBs managing a single fleet in SimpleMDM with multiple network segments, employees, contractors, and managed guest devices, each landing in the correct VLAN automatically, driven by the group structure in SimpleMDM.
SecureW2 automatically revokes certificates when a device’s status changes in SimpleMDM. The SimpleMDM Identity Lookup Provider queries device status using API credentials at revocation time. If a device is unenrolled or removed, SecureW2 triggers the revocation workflow. The revoked certificate fails EAP-TLS authentication at the next network connection. Cloud RADIUS checks certificate validity, including CRL status, at authentication time. The device loses network access without manual intervention.
SimpleMDM device enrollment state and group membership also drive VLAN assignment at authentication time through Cloud RADIUS. The Identity Lookup Provider retrieves the authenticating device’s enrollment status and attributes, and Cloud RADIUS evaluates those against policy rules to return a RADIUS Access-Accept with the appropriate VLAN tag and access level. A managed, enrolled device in the Corporate Devices Assignment Group receives full network access, a device flagged for review receives a restricted internet-only VLAN, and a device not found in SimpleMDM is denied entirely. VLAN assignment is evaluated at every authentication, so changes in SimpleMDM device state take effect at the next connection attempt.
Frequently Asked Questions
Connect with our integration specialists to implement this solution in your environment and transform your security posture.