Skip to main content

Back to Secure IT

The network recognises the device, not the password

We introduce certificate-based network access: 802.1X with EAP-TLS, a PKI your team can operate, and segmentation that genuinely contains an incident.

30 minutes · no sales pitch · an honest read on whether we fit

A fit when

  • Your network access depends on shared passwords
  • You are migrating away from a legacy NPS or AD CS installation
  • An audit requires controlled network access
  • Production and office share a network and need separating

The situation

  • Wi-Fi access depends on a shared password that everyone knows and nobody rotates.
  • An unknown device on the network goes unnoticed because there is no access control.
  • A legacy Microsoft NPS and AD CS installation runs, but nobody dares to touch it.
  • Guests and third-party devices end up on the same network as production.

What we do

We build access control with the tool that fits you: PacketFence, SCEPman or Microsoft AD CS. Devices and users authenticate by certificate over 802.1X with EAP-TLS, certificates are delivered through Intune, and VLAN and access-list assignment follows what the device actually is. Guests and third-party devices get their own documented path.

What is included

  • 01Access control designWhich device classes exist, where they may go, and what happens when a device is unknown.
  • 02A PKI that stays operableCertificate authorities with SCEPman, PacketFence CA or AD CS, including renewal and revocation.
  • 03802.1X in productionEAP-TLS for users and devices, dynamic VLAN and access-list assignment, introduced in stages.
  • 04Certificates through IntuneAutomatic delivery and renewal over SCEP, so nobody installs certificates by hand.

What you end up with

Certificate-based network accessOperable PKI with renewalDocumented segmentationA separate path for guests
Request a briefingA reply within 1 business day, from a person.