Back to Customer Stories
K-12
2min read
September 13, 2021

School District Secures Wi-Fi With Cloud RADIUS

This school district in the mid-west of the United States proudly teaches over 3,000 K-12 students.

The Challenge: After struggling with forgotten and shared passwords, the school sought EAP-TLS authentication for better visibility and protection of its Wi-Fi network.

Deployment Timeline

This school district has over 3,000 students across three elementary schools, a middle school, and a high school. They were looking to transition to a certificate-backed EAP-TLS network, while still leveraging their current network environment.

Originally, they attempted to utilize their already existing FreeRADIUS to authenticate certificates but found the process too difficult. They considered hiring a FreeRADIUS expert to help them transition but found this to be too expensive a solution.

They contacted SecureW2 in June 2021 and were fully equipped with an EAP-TLS network ready for students in the Fall.

Challenges

The school was using FreeRADIUS with EAP-PEAP but were having trouble with students forgetting and sharing their password.

Quote Icon
"You really can’t rely on student discretion when it comes to keeping passwords secure. We needed increased network visibility to protect the integrity of our Wi-Fi, but using FreeRADIUS with our on-premise directory was expensive. "
AAMIR, NETWORK INFRASTRUCTURE SPECIALIST

Their managed devices were mostly Chromebooks so they originally considered using G-Suite with FreeRADIUS with a custom PKI for EAP-TLS but found that they would have to purchase the most expensive Google license to work with their AD-CS and on-premise directory. The school also needed a way for students with a varying range of computer literacy to be able to self-enroll their BYOD devices with certificates, while also easily pushing certificates onto their managed devices.

Quote Icon
"It was a relief that we didn’t need to buy all new infrastructure to support passwordless authentication. SecureW2’s support team helped us integrate our controllers, Ubiquiti access points, and servers to leverage our existing identities for certificate issuance. "
AAMIR, NETWORK INFRASTRUCTURE SPECIALIST

Solution

After several internal meetings and a trial period, the school district decided to go with SecureW2’s PKI service to integrate because it would integrate seamlessly with their Google and AD environment.

Quote Icon
"We needed a solution that was just plug and play with our current network infrastructure. That’s exactly what we got with SecureW2."
AAMIR, NETWORK INFRASTRUCTURE SPECIALIST

SecureW2 onboarding software communicates with G-Suite, granting trust to the end-user and issuing a certificate. Certificates offer the best form of network security due to their high-level encryption that’s nearly impossible to crack. The client can then present the certificate to the RADIUS server to be authenticated and authorized for secure network access.

Using SecureW2, students bringing their own devices can easily issue custom certificates for themselves through JoinNow to access the school’s network. The best part? These certificates are cryptographically linked to the user, so there is no risk of sharing certificates and you can rest assured that users are who they say they are.

Evaluating Success

SecureW2 an industry-leading Cloud PKI made enrolling the school’s Chromebooks and other devices for certificate-based authentication a breeze. Because our software requires no prior knowledge of PKIs and is easily integrated into their existing network environment, the IT team was able to get their network set up before the next school year began.

With a fully functional management portal, the IT department can easily manage and revoke certificates and stay aware of the comings and goings of their network.

Quote Icon
"Having full visibility of network activity has made our job so much easier. "
AAMIR, NETWORK INFRASTRUCTURE SPECIALIST

Learn More About SecureW2

Explore SecureW2's trust model, dive into our platform and product details or read more success stories.

Why SecureW2

Establish continuous trust with Dynamic PKI and Cloud RADIUS. Enforce access based on live identity, device posture, and risk context.

  • Passwordless authentication that can’t be phished
  • Works with your IdP, MDM, and security stack
  • Real-time policy engine for dynamic access control
Explore the Platform

Get the essentials on the products that power continuous enforcement.

Knowledge Base Articles

Explore practical guidance from engineers and admins deploying SecureW2.

  • Setup and configuration tutorials
  • Integration best practices with IdPs and MDMs
  • Troubleshooting guides for PKI and RADIUS