SOTI transforms device identity data into dynamic network policies that adapt to device trust in real time. Issue phishing-resistant certificates to every managed device through SOTI MobiControl, including rugged handhelds, clinical tablets, and shared kiosk endpoints.
Overview
SecureW2 integrates with SOTI MobiControl to provide certificate-based Wi-Fi and network authentication for enterprise mobile fleets, including ruggedized handhelds, barcode scanners, mobile workstations, and Android devices in field service, retail, healthcare, and manufacturing. The integration links MobiControl device management to JoinNow Dynamic PKI and JoinNow Cloud RADIUS, replacing shared Wi-Fi passwords and static SCEP secrets with per-device x.509 certificates provisioned automatically via MobiControl profiles.
When a device enrolls in MobiControl, it receives an SCEP certificate profile that triggers automated enrollment with SecureW2. The Policy Engine validates the device against MobiControl before issuing credentials, and Cloud RADIUS performs a live lookup to MobiControl at every authentication event to reflect the device’s current enrollment state. This results in a fully cloud-native certificate authentication stack built for enterprise mobile operations, without on-premises PKI infrastructure or shared passwords.
SOTI MobiControl delivers a SCEP certificate profile containing a unique per-device challenge to each managed endpoint. CloudConnector receives the SCEP request and sends a challenge webhook to MobiControl to validate the device identity before any credential is issued. Once validated, Dynamic PKI issues a device-bound certificate that is delivered to the device keychain automatically and used for 802.1X EAP-TLS network authentication.
Shared and rugged devices authenticate using device certificates; no user identity is required at the network edge. At each connection attempt, Cloud RADIUS performs a live query to SOTI MobiControl to verify the device record is still enrolled and active before returning a RADIUS decision. Devices removed from MobiControl receive a RADIUS Reject at the next authentication event, even if their certificate has not yet expired.
Ruggedized devices in warehouses, fields, and retail environments are replaced, repaired, and redeployed more frequently than office endpoints. Each lifecycle event, device returned for repair, swapped for a replacement unit, or moved to a different MobiControl group, needs to be reflected in the network access layer without IT intervention. When a device is unenrolled from SOTI MobiControl, Cloud RADIUS detects the missing device record and denies access, even if the device still holds a valid certificate.
When a replacement unit is enrolled and assigned a SCEP profile by MobiControl, SecureW2 issues a fresh certificate automatically. The new device inherits the same network access as the unit it replaced, based on its MobiControl group membership, with no manual RADIUS configuration required. The replacement cycle is transparent to the network team.
For high-churn fleets where dozens of devices turn over each month, this model eliminates coordination overhead between MDM administrators and network engineers. Device lifecycle is managed in MobiControl; network access policy enforces itself at every authentication without human involvement.
Cloud RADIUS reads MobiControl device group membership at authentication time and maps group values to RADIUS policy attributes, including VLAN assignments. This supports network segmentation scenarios common in enterprise mobile operations, separating warehouse floor devices from office devices, isolating contractor-owned devices from corporate infrastructure, or placing devices under remediation into a restricted segment. A device in the "Warehouse Floor" group can receive a VLAN scoped to warehouse management systems only, while a device in "Contractor Devices" receives an internet-only VLAN, and a device not found in MobiControl receives a RADIUS Reject.
Because VLAN assignment is evaluated at every authentication event, changes in MobiControl group membership take effect at the next connection attempt. No static VLAN assignments are stored in the certificate, and no manual RADIUS policy updates are required when devices are reassigned between groups, transferred between locations, or decommissioned.
Frequently Asked Questions
Connect with our integration specialists to implement this solution in your environment and transform your security posture.