Enrolling ADCS Certificates and Installing them on BYOD Devices
With SecureW2βs #1 Rated Onboarding Client, organizations can easily install certificates and configure certificate-based WPA2-Enterprise Wi-Fi settings on any BYOD device. With solutions for every Operating System, all you need to do is direct users to the SecureW2 Landing Page and their OS will be detected, with the appropriate Onboarding Client deployed to their device. From there, they go through a one-time configuration. They enter in their credentials, and the client will enroll them for a unique client certificate and configure their device to use that certificate for secure network access.
Configure the Landing Page and Onboarding Clients
The first step in integrating ADCS with SecureW2, is using our Getting Started Wizard. This will configure default settings for everything you need for WPA2-Enterprise Certificate-Based Authentication.
- Navigate toΒ Device OnboardingΒ βΒ Getting Started
- Configure the appropriate settings on the Wizard like the Image below. Make sure the SSID name matches the SSID we will configure later for certificate authentication.
- After the Wizard finishes running, navigate toΒ Device OnboardingΒ βΒ Network Profiles
- ClickΒ ViewΒ on the newly generated Network Profile and you will be redirected to your new Landing Page
Now that weβve got our Landing Page and Onboarding Clients, we need to configure them to generate certificate with our ADCS Root CA. After that, we will configure network settings, go over methods of distributing the Landing Page, and you will be all set to get certificates on your BYOD devices.
Import your ADCS Certificate to SecureW2
Start by downloading your Root CA from ADCS. Once youβve done that, we can import them into SecureW2.
- Navigate toΒ Device OnboardingΒ βΒ Network ProfilesΒ and clickΒ EditΒ on your Network Profile.
- Under theΒ CertificatesΒ tab, selectΒ Add/Remove CertificateΒ
- Under theΒ Private CertificateΒ option, clickΒ Choose FileΒ and select your ADCS Root CA
- ClickΒ Upload
- ClickΒ Update
- Under theΒ Network SettingsΒ tab, clickΒ EditΒ on your Network Setting. Here we need to configure Server Certificate Validation is setup on our devices with our ADCS CA
- Under theΒ Server CertificateΒ tab, ensure thatΒ Enable Server Certificate ValidationΒ is checked
- UnderΒ Specify CA CertificatesΒ checkΒ TrustΒ on your ADCS Root CA and uncheckΒ TrustΒ on the CA included by default (GeoTrust)
- Ensure that theΒ Connect to these server namesΒ setting is configured for the organization that your CA belongs to.
- ClickΒ Update
- Now you canΒ DeleteΒ the CA that is included in the Network Profile by default (GeoTrust)
- UpdateΒ your settings.
- ClickΒ RepublishΒ on your Network Profile to push your recently configure settings.
Now your Onboarding Clients will enroll devices for a client certificate issued by your ADCS Root CA and you can test them accordingly. Now all thatβs left is to configure your Access Points and RADIUS Server for certificate-based authentication and direct the SecureW2 landing page to your users.
Direct Users to the Landing Page
There are several ways to get users to the SecureW2 landing page. We typically recommend configuring an βOnboarding SSIDβ, Open SSID that is restricted to SecureW2 resources and redirects to our Landing Page, and getting users to configure their devices at home or using mobile data. For more information on creating Onboarding SSIDs,Β visit our Wi-Fi integrations pageΒ for integration guides for the major networking vendors.
Using AD CS to Issue Certificates to Managed Devices
Our powerful certificate enrollment gateway will enable any MDM you choose (Jamf, Airwatch, Intune, GPO, Google Workspace, etc.) to push configuration payloads to your managed devices for automatic self-enrollment of certificates. For more info on supported systems, check out ourΒ managed device solutions page.
Below is an example that illustrates the ease with which you can use Jamf and SCEP to issue your AD CS certificates to all of your managed devices in just a few minutes.
Configure SCEP Gateway API in SecureW2
- Use our Getting Started Wizard to generate a shared secret key and an access token.
- Following the prompts, use the shared secret and the token to create a new SCEP URL.Β This URL will later be pushed to your devices to enable auto-enrollment for certificates.
- The last step is to create your Enrollment Policies. These can differ based on the needs of an organization, but most users will choose a setup similar to the one pictured below.
Configure Certificate Template for SCEP Gateway
- Insert the SCEP URL you previously created. It contains all the necessary instructions for your MDMs to configure themselves to request client certificates from SecureW2.The screenshot below is an example of a typical config for Jamf-managed devices.
Push the Payload to Your MDM
- Now that your configuration profile (the βpayloadβ of network settings) is properly set up, you can push it to your devices through the recently configured SCEP Gateway.
Create an SSID for AD CS Certificate-Based Authentication
Now that weβve configured SecureW2 to enroll our devices for certificates and configure them for certificate-based Wi-Fi, we need to create an SSID to use with our certificates.
Creating the SSID is quite easy, as all we need to do is make sure the name of the SSID matches the name on our Network Profile (you can change this later in the Network Settings), and the SSID points to a configured RADIUS Server. For more information about this,Β visit our Wi-Fi integrations page for detailed integration guides for all the Wi-Fi vendors.
Configuring the RADIUS Server is where most of the work comes in, but even this isnβt overly complex. If you choose to use the SecureW2 RADIUS Server, there is zero work involved after you enter the RADIUS details.
Configure the RADIUS Server
In a nutshell, configuring your existing RADIUS Server for certificate-based authentication takes 3 steps.
- Importing the ADCS Root CA to your RADIUS Server trust list
- Configuring the RADIUS Server to use the SecureW2 CRL
- And Identity Lookup if supported by your RADIUS Server. (Identity Lookup is supported by SecureW2βs RADIUS Server.)
- Configuring any authentication policies, like segmenting your network into VLANs
For more information about this, you can visit ourΒ RADIUS Integrations PageΒ where we have detailed guides on how to integrate the SecureW2 PKI with all the major RADIUS servers. We also offer white-glove support on deployments, so head on over to ourΒ Free DemoΒ page and see for yourself how SecureW2 can revolutionize your network security.


