Deploy X.509 certificates to iOS, Android, macOS, and Windows through Workspace ONE UEM, ACME for Apple devices with hardware attestation, Dynamic SCEP for Windows and Android via Workspace ONE’s built-in SCEP relay. Cloud RADIUS enforces live Workspace ONE compliance at every connection and integrates with CrowdStrike and Entra ID for multi-signal posture enforcement across the entire fleet.
Overview
SecureW2 integrates with VMware Workspace ONE UEM to automate certificate enrollment across iOS, Android, macOS, and Windows devices without shared secrets, user interaction, or manual provisioning. Workspace ONE configuration profiles issue certificates using ACME for Apple devices and Dynamic SCEP for Windows and Android, with JoinNow Dynamic PKI handling issuance and lifecycle management.
JoinNow Cloud RADIUS enforces access policy at authentication time by performing a live compliance lookup against Workspace ONE at every connection attempt. Devices that fall out of compliance lose network access automatically. Large enterprises running Workspace ONE alongside CrowdStrike and Entra ID benefit from a direct multi-signal integration: SecureW2 queries Workspace ONE for device enrollment state, Entra ID for user identity and group membership, and CrowdStrike for device risk score, combining all three into a single RADIUS policy decision that enforces consistent access standards across platforms.
Workspace ONE’s built-in SCEP proxy relay forwards certificate requests to JoinNow CloudConnector, generating a unique per-device challenge for each request. This challenge is verified by CloudConnector to ensure that the requesting device is a known managed device in Workspace ONE, eliminating the static shared secret used in traditional SCEP. Since the challenge is valid for a single use and tied to the specific device identity, it cannot be intercepted and replayed by another device.
Cloud RADIUS dynamically manages access controls by querying Workspace ONE user and device attributes during every authentication event. This eliminates the need for static VLAN assignments and manual policy updates. During the EAP-TLS handshake, the device presents its certificate, which is validated by Cloud RADIUS. It then retrieves group membership, compliance state, and enrollment status from Workspace ONE. Based on these attributes, RADIUS policy maps them to network outcomes. Compliant devices gain full access on their assigned VLAN, while non-compliant devices are restricted to a restricted segment. Unenrolled devices are denied access before reaching internal resources.
ACME (Automatic Certificate Management Environment) is Apple’s preferred enrollment protocol for devices. It integrates with Apple Managed Device Attestation (MDA) to cryptographically prove a device’s identity before issuing credentials.
When a device initiates ACME enrollment, it contacts Apple’s attestation server, which returns a signed attestation statement containing the device’s serial number, hardware model, unaltered OS image confirmation, and proof that the certificate private key is bound to the Secure Enclave.
After validating attestation, the JoinNow Policy Engine queries Workspace ONE Identity Lookup Provider to confirm active management in Workspace ONE UEM. SecureW2 cross-references the attested serial number against Workspace ONE device records. Devices that pass hardware attestation but aren’t found in Workspace ONE don’t receive certificates. Supported platforms are macOS, iOS (16+), and iPadOS (16+).
Once configured, enrollment is automated. Workspace ONE distributes the .mobileconfig profile through standard deployment, and devices enroll without user interaction.
Cloud RADIUS evaluates multiple posture signals simultaneously at every authentication event. In a Workspace ONE environment co-deployed with CrowdStrike Falcon and Microsoft Entra ID, JoinNow queries Workspace ONE for device enrollment and compliance state, Entra ID for user identity and group membership, and CrowdStrike for real-time device risk score at each connection attempt. Each signal is evaluated independently, and policy rules define how combinations map to access outcomes.
A device can be fully compliant in Workspace ONE but denied access if CrowdStrike flags an active threat. The RADIUS policy enforces both conditions. A device that clears all three checks receives access on the VLAN determined by its Entra ID group membership. This closes the gap between endpoint security and network admission. A CrowdStrike detection triggers automatic network isolation at the device’s next connection attempt, without administrator intervention.
CrowdStrike integration is available in the SecureW2 Apex Ultimate bundle. The Workspace ONE Identity Lookup Provider and Entra ID lookup are available in standard JoinNow configurations. All three can be chained in a single RADIUS policy rule with no additional infrastructure required.
Frequently Asked Questions
Connect with our integration specialists to implement this solution in your environment and transform your security posture.