Zum Hauptinhalt springen

How do you push WiFi certificates with Intune?

Intune sends each managed device a trusted root certificate, a SCEP profile that requests a client certificate, and a WiFi profile set to EAP-TLS. With Purple, the device requests its certificate from Purple and authenticates against Purple’s cloud RADIUS. Setup takes around 5 to 10 minutes, once, for the whole organisation.

Why Intune alone is not enough

Intune is the delivery mechanism. Certificate-based WiFi also needs a certificate authority to issue each device its certificate and a RADIUS server to check that certificate when the device joins. Building that yourself means a PKI, its revocation endpoints and a RADIUS service that trusts it.

Purple supplies both halves. The device picks up the Intune policy, asks Purple for a certificate carrying the user’s identity, and Purple checks your directory before issuing it, so only people who still work for you get one.

How it works with Purple

  1. Set Purple up in Intune

    Trust two certificates and add two profiles. Around 5 to 10 minutes, once, for the whole organisation.

  2. The device asks for a certificate

    It picks up the policy and calls Purple directly over SCEP, carrying the user’s identity.

  3. Purple issues it

    Checked against your directory first, so a certificate is only minted for someone still in it.

  4. The device connects

    It authenticates to Purple’s cloud RADIUS over WPA2 or WPA3-Enterprise. The person does nothing.

What is supported

Delivery
A certificate profile plus a WiFi profile, deployed over SCEP.
Platforms
Windows, macOS, iOS and Android devices managed by Intune.
Certificate authority
Purple issues the certificate. The private key is generated on the device and held in its secure hardware.
Identity check
A callback to your identity provider on every issue, so a certificate is only minted for someone still in your directory.
Personal devices
The same SSID and the same cloud RADIUS, with the certificate installed through the Purple app instead of Intune.
Access points
Any enterprise access point that speaks RADIUS, including Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. You reconfigure the SSID, not the hardware.
Certification
Purple is ISO 27001 certified, and GDPR and CCPA compliant.

What Purple does not do

  • You cannot bring your own certificate authority. Purple’s RADIUS authenticates against Purple’s backend, so the certificate has to be one Purple issued.
  • Purple does not replace Intune and does not read from it. It sees a device’s MAC address, serial number and certificate details, not its name, owner, compliance state or operating system.
  • Purple does not check whether a device is patched or encrypted. Posture checking stays with your MDM.
  • The directory sync runs roughly hourly, and revocation applies to the next authentication rather than cutting a live session.

Every statement above about what Purple does is taken from Certificate-based WiFi via MDM and Staff WiFi.

Intune and cloud RADIUS: questions

How do you push WiFi certificates with Intune?

Intune sends each managed device a trusted root certificate, a SCEP profile that requests a client certificate, and a WiFi profile set to EAP-TLS. With Purple, the device requests its certificate from Purple and authenticates against Purple’s cloud RADIUS. Setup takes around 5 to 10 minutes, once, for the whole organisation.

Does the user have to do anything?

No. They log in to the laptop they were issued and it is on the WiFi. There is no app to install and no sign-in step on an Intune-managed device. The Purple app is the separate route for personal devices.

Can we use our own certificate authority or Microsoft Cloud PKI?

No. Purple’s RADIUS authenticates against Purple’s backend, so the certificate has to be one Purple issued. Most teams asking are trying to stop running certificate infrastructure, which this removes.

Which device management systems does Purple support besides Intune?

JumpCloud, IRU (formerly Kandji) and Jamf Pro. The mechanism is SCEP, an open standard, so other systems are likely to work, but Purple has not tested them.

Does Purple check Intune compliance before a device joins?

No. Purple does not read from Intune and does not check whether a device is patched or encrypted. Posture checking stays with your MDM, and Purple handles onboarding, certificate lifecycle and attribution.

Zuletzt geprüft:

Speak to an expert

Tell us what you need and we'll be in touch.