Saltar al contenido principal

How to Configure SCEP for Secure BYOD and 802.1X Network Authentication

Esta guía proporciona una referencia técnica detallada para configurar SCEP con el fin de implementar la autenticación de red 802.1X basada en certificados. Cubre la transición arquitectónica de contraseñas compartidas a EAP-TLS, la integración con la gestión de dispositivos móviles (MDM) y una segmentación de red estricta para un acceso BYOD seguro en entornos empresariales.

📖 4 min de lectura📝 888 palabras🔧 2 ejemplos prácticos3 preguntas de práctica📚 8 definiciones clave

Escuchar esta guía

Ver transcripción del podcast
Hello, and welcome to this technical briefing from Purple. I'm your host, and today we're getting into the detail on SCEP - the Simple Certificate Enrollment Protocol - and how to configure it correctly for secure BYOD and 802.1X network authentication. If you're an IT manager, a network architect, or a CTO responsible for WiFi infrastructure across a hotel group, a retail estate, a stadium, or a public-sector organisation, this is directly relevant to you. We're not doing theory today. We're doing architecture and decisions. Let's get into it. [SECTION: Introduction and Context - approximately 1 minute] Here's the problem you're likely facing. You have staff devices, contractor laptops, and personal phones all needing network access. You've probably got a mix of managed and unmanaged devices. And somewhere in your infrastructure, there's still a shared WPA2 pre-shared key that twelve people know, three of whom left the company last year. That's not a security posture. That's a liability. The answer is 802.1X - the IEEE standard for port-based network access control. It ensures no device passes traffic until it's been explicitly authenticated. But 802.1X is just the framework. The real question is what authentication method sits inside it. And for BYOD at scale, the answer is EAP-TLS with certificates provisioned via SCEP. That's what we're unpacking today. [SECTION: Technical Deep-Dive - approximately 5 minutes] Let's start with what SCEP actually does. SCEP - Simple Certificate Enrollment Protocol - was originally published as an Internet Draft by the IETF in 1999, created by VeriSign. It was formalised as RFC 8894. Its job is straightforward: automate the process of issuing X.509 digital certificates to devices at scale, without requiring a human to manually generate and install each one. Here's the four-step flow. Step one: the device connects to a SCEP endpoint - a URL hosted either on-premises via a Windows Server role called NDES, the Network Device Enrollment Service, or via a cloud PKI provider. This URL is the gateway to your Certificate Authority. Step two: the device presents a SCEP challenge - a shared secret that proves it's authorised to request a certificate. In an MDM-managed environment like Microsoft Intune, this challenge is delivered dynamically and uniquely per device, which is far more secure than a static password shared across all devices. Step three: the device generates its own private and public key pair locally. It creates a Certificate Signing Request - a CSR - using the public key and sends that to the SCEP server. Here's the critical security point: the private key never leaves the device. It's generated locally, stored in the device's secure enclave - that's the TPM on Windows or the Secure Enclave on iOS - and is never transmitted. This is why SCEP is the right choice for network authentication, not PKCS, where the CA generates the key centrally and has to push it to the device. Step four: the Certificate Authority validates the CSR, signs it with the CA's private key, and returns the signed X.509 certificate to the device. The device now has a unique cryptographic identity. Now, how does that certificate get used for 802.1X authentication? When the device connects to your WiFi SSID, the access point - whether that's Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, or Ubiquiti UniFi - acts as the authenticator. It doesn't make the authentication decision itself. It forwards the EAP exchange to your RADIUS server. That could be Microsoft NPS, Cisco ISE, or Aruba ClearPass. The RADIUS server initiates an EAP-TLS handshake. The device presents its SCEP-provisioned client certificate. The RADIUS server validates three things: the certificate chain back to the trusted root CA, the certificate expiry date, and whether the certificate has been revoked - checked against a Certificate Revocation List, or CRL, or via OCSP, the Online Certificate Status Protocol. If all three checks pass, the RADIUS server sends an EAP-Success message, and the access point opens the port. The device is on the network. This is mutual authentication. The device also validates the RADIUS server's certificate. If someone sets up a rogue access point, the device will reject it because the server certificate won't validate against the trusted CA. That's your protection against evil twin attacks. Now let's talk about the deployment sequence in Microsoft Intune, because that's the most common MDM platform we see in enterprise environments. You deploy three Intune configuration profiles, in strict order. First, the Trusted Root Certificate profile - this pushes your root CA certificate to every device so they trust your PKI. Second, the SCEP Certificate profile - this tells devices the SCEP URL, the subject name format, the key usage, and the extended key usage for client authentication. The OID for client authentication is 1.3.6.1.5.5.7.3.2. Third, the WiFi profile - this specifies the SSID, sets the security type to WPA2-Enterprise or WPA3-Enterprise, sets the EAP type to EAP-TLS, and links to the SCEP certificate profile. The order matters. The WiFi profile has a dependency on the SCEP profile, which has a dependency on the Trusted Root profile. Deploy them out of sequence and you'll get errors. One architectural decision you need to make is where to host the NDES server. It needs to be reachable from the internet so devices can enrol before they arrive on-site. The secure way to do this is to publish the NDES URL via Microsoft Entra ID Application Proxy. This avoids opening inbound firewall ports and lets you apply Conditional Access policies to the enrolment flow. For organisations that want to eliminate on-premises infrastructure entirely, cloud PKI providers - Microsoft's own Cloud PKI in Intune, or third-party options - remove the NDES dependency completely. [SECTION: Implementation Recommendations and Pitfalls - approximately 2 minutes] Let me give you the three most common failure modes we see. Failure mode one: group targeting mismatch. This is the most frequent cause of WiFi profile deployment failures in Intune. If your Trusted Root profile is assigned to a User group, your SCEP profile to a Device group, and your WiFi profile to a different User group, Intune cannot resolve the dependency chain. All three profiles must target the exact same Azure AD group - either all Users or all Devices. Pick one and be consistent. Failure mode two: CRL availability. Your RADIUS server checks the CRL to verify certificates haven't been revoked. If the CRL Distribution Point - the CDP URL embedded in the certificate - is unreachable, authentication fails for every device. This is a common cause of mass outages after network changes. Ensure your CDPs are highly available, ideally published to both an internal URL and an external URL for remote devices. Consider OCSP as a more resilient alternative to CRL checking. Failure mode three: not enforcing server certificate validation on clients. This is the single most impactful misconfiguration in 802.1X deployments. If your MDM-deployed WiFi profile doesn't specify the trusted CA and the expected RADIUS server name, devices will connect to any server presenting any certificate. That defeats the entire purpose of EAP-TLS. Always configure server validation in your WiFi profile. [SECTION: Rapid-Fire Q and A - approximately 1 minute] Let's do a few quick questions. Question: Do we need WPA3? Yes. Migrate to WPA3-Enterprise. It mandates Protected Management Frames, which blocks deauthentication attacks. All hardware from Cisco Meraki, HPE Aruba, Ruckus, and Juniper Mist supports it. Question: What about devices that can't support 802.1X - like IoT sensors or legacy printers? Use MAC Authentication Bypass as a fallback, but place those devices on a heavily restricted VLAN with no access to corporate resources. Question: How does Purple fit into this? Purple's Guest WiFi platform handles the visitor and guest access layer - the captive portal, the data capture, the analytics. Your 802.1X and SCEP infrastructure handles staff and managed device access. They run on separate SSIDs and separate VLANs. Purple integrates with Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme, and Fortinet - so your hardware investment is protected. [SECTION: Summary and Next Steps - approximately 1 minute] To wrap up. SCEP automates certificate issuance at scale. The private key stays on the device - that's the security advantage over PKCS. Deploy via MDM in strict sequence: Trusted Root, then SCEP profile, then WiFi profile, all targeting the same group. Publish NDES via Application Proxy or move to cloud PKI. Enforce CRL or OCSP checking on your RADIUS server. And always configure server certificate validation on client supplicants. If you're still running a shared pre-shared key for staff WiFi, that's the change to make this quarter. The certificate infrastructure is more work upfront, but it eliminates an entire class of credential-based attacks and typically reduces WiFi-related helpdesk tickets by 70 to 80 percent once deployed. For the full technical guide, architecture diagrams, and worked examples, visit purple dot ai. Thanks for listening.

header_image.png

Resumen ejecutivo

Para los responsables de TI y arquitectos de red que operan en entornos empresariales, la gestión del acceso WiFi para BYOD (Bring Your Own Device) ha pasado de ser una función de conveniencia a un imperativo de seguridad crítico. Depender de claves precompartidas o de Captive Portals básicos para el WiFi del personal es una vulnerabilidad de seguridad y un cuello de botella operativo. La arquitectura de red moderna exige una autenticación 802.1X mediante EAP-TLS, lo que garantiza que cada dispositivo se verifique criptográficamente antes de acceder a la red.

Esta guía proporciona un marco pragmático y neutral respecto al proveedor para implementar un acceso WiFi BYOD seguro mediante el Protocolo de inscripción de certificados simple (SCEP). Detallamos las configuraciones precisas necesarias para proteger el extremo de la red empresarial moderna, centrándonos en la implementación de la autenticación 802.1X, el aprovechamiento de la gestión de dispositivos móviles (MDM) para el cumplimiento normativo y la aplicación de una segmentación de red estricta. Al asociar estos controles técnicos con los resultados empresariales, los líderes de TI pueden implementar soluciones que protejan la integridad de los datos al tiempo que mantienen la eficiencia operativa.

Análisis técnico detallado: Arquitectura SCEP y 802.1X

La base de un acceso WiFi BYOD seguro radica en abandonar las contraseñas compartidas en favor de un control de acceso basado en la identidad.

El estándar 802.1X y EAP-TLS

El estándar IEEE 802.1X es la base no negociable para la seguridad WiFi empresarial. Proporciona control de acceso a la red basado en puertos (PNAC), lo que garantiza que un dispositivo no pueda comunicarse en la red hasta que haya sido autenticado explícitamente. Para las implementaciones BYOD, EAP-TLS (Transport Layer Security) es el estándar de oro. EAP-TLS se basa en certificados X.509 del lado del cliente, lo que elimina el riesgo de robo de credenciales y ataques de intermediario (man-in-the-middle).

SCEP (Simple Certificate Enrollment Protocol)

Para implementar estos certificados a escala, SCEP automatiza la emisión y gestión de certificados dentro de una infraestructura de clave pública (PKI). En un flujo de trabajo de SCEP, el servicio MDM indica al extremo que genere su propio par de claves pública y privada. A continuación, el dispositivo crea una solicitud de firma de certificado (CSR) y la envía a través de un servidor de servicio de inscripción de dispositivos de red (NDES) a su autoridad de certificación (CA).

La ventaja de seguridad crítica de SCEP es que la clave privada nunca sale del dispositivo. Se genera localmente y se almacena en el enclave seguro del dispositivo (como el TPM en Windows o el Secure Enclave en iOS).

scep_architecture_overview.png

Guía de implementación: La secuencia de despliegue

Configurar correctamente SCEP para 802.1X requiere un cumplimiento estricto de una secuencia de despliegue específica. Las dependencias de los perfiles de Intune dictan que se debe establecer la confianza antes de poder configurar la autenticación.

Paso 1: Desplegar el perfil de certificado raíz de confianza

Antes de que cualquier dispositivo pueda solicitar un certificado de cliente o confiar en su servidor RADIUS, debe confiar en la autoridad de certificación emisora. Exporte su certificado de CA raíz como un archivo .cer y despliegue este perfil en sus grupos de dispositivos de destino.

Paso 2: Configurar el perfil de certificado SCEP

Configure el perfil SCEP para indicar a los dispositivos cómo obtener su certificado de cliente. Vincule este perfil al perfil de certificado raíz de confianza creado en el Paso 1 y proporcione la URL externa de su servidor NDES.

Paso 3: Desplegar el perfil WiFi 802.1X

El paso final consiste en enviar la configuración WiFi que vincula los certificados al SSID de la red. Establezca el tipo de seguridad en WPA2-Enterprise o WPA3-Enterprise, configure el tipo de EAP en EAP-TLS y seleccione el perfil de certificado SCEP creado en el Paso 2 como el certificado de autenticación del cliente.

scep_vs_pkcs_comparison.png

Buenas prácticas y segmentación de red

Al implementar el despliegue de certificados SCEP, siga estas buenas prácticas neutrales respecto al proveedor para garantizar el cumplimiento y la fiabilidad.

Arquitectura estricta de tres zonas

Una red plana es una red comprometida. Implemente una segmentación estricta:

  1. Zona corporativa: Dispositivos gestionados propiedad de la empresa con acceso total a los recursos internos.
  2. Zona BYOD: Dispositivos propiedad de los empleados con acceso a Internet y acceso restringido a aplicaciones internas específicas.
  3. Zona de invitados: Dispositivos de visitantes solo con acceso a Internet y aislamiento de clientes habilitado.

Ubicación del servidor NDES

Publique la URL de NDES utilizando el proxy de aplicaciones de Microsoft Entra ID. Esto proporciona un acceso remoto seguro sin abrir puertos de firewall entrantes y le permite aplicar políticas de acceso condicional al flujo de inscripción.

WPA3-Enterprise y OpenRoaming

Realice la transición de WPA2 a WPA3-Enterprise para beneficiarse de las tramas de gestión protegidas (PMF) obligatorias. Para una conectividad segura y sin interrupciones en diferentes ubicaciones, considere la posibilidad de implementar OpenRoaming. Purple actúa como un proveedor de identidad gratuito para OpenRoaming bajo la licencia Connect, lo que simplifica el acceso seguro sin necesidad de un registro manual.

Resolución de problemas y mitigación de riesgos

Incluso con una planificación meticulosa, el despliegue de certificados puede presentar problemas.

Discrepancias en la asignación de grupos

Si el perfil SCEP se asigna a un grupo de usuarios, pero el perfil WiFi se asigna a un grupo de dispositivos, el MDM no podrá resolver la dependencia. Asegúrese de que los perfiles de raíz de confianza, SCEP y WiFi estén todos desplegados en el exactúen en el mismo grupo.

Comprobación de RADIUS y CRL

Si se revoca el certificado de un dispositivo, el servidor RADIUS debe saberlo de inmediato. Configure su Servidor de directivas de redes (NPS) o servidor RADIUS para aplicar una comprobación estricta de la Lista de revocación de certificados (CRL). Asegúrese de que sus Puntos de distribución de CRL (CDP) tengan una alta disponibilidad.

ROI e impacto empresarial

La transición a la implementación de certificados SCEP 802.1X ofrece un retorno medible tanto en seguridad como en operaciones.

  1. Reducción de tickets de soporte: El acceso WiFi basado en contraseñas genera un volumen significativo de tickets de soporte. La autenticación basada en certificados es invisible para el usuario, lo que suele reducir el volumen de soporte relacionado con WiFi en un 70%.
  2. Mayor nivel de seguridad: EAP-TLS elimina el riesgo de robo de credenciales. Esto es fundamental para el cumplimiento de marcos como PCI DSS y GDPR, especialmente en entornos sanitarios y de comercio minorista.
  3. Incorporación fluida: La integración de SCEP con los flujos de trabajo de MDM existentes garantiza una experiencia de aprovisionamiento unificada y sin intervención (zero-touch) desde el primer día.

Para obtener más información sobre temas relacionados, consulte WiFi para invitados , Analíticas de WiFi y nuestra guía Enterprise WiFi Security: guía completa para 2026 .

Definiciones clave

SCEP (Simple Certificate Enrollment Protocol)

A protocol that allows devices to request digital certificates from a Certificate Authority, where the private key is generated and stored securely on the device itself.

The recommended method for deploying WiFi authentication certificates due to its high security and scalability.

EAP-TLS (Extensible Authentication Protocol - Transport Layer Security)

The most secure 802.1X authentication method, requiring both the server and the client to present valid digital certificates.

The target authentication protocol that the MDM WiFi and certificate profiles are designed to enable.

802.1X

An IEEE standard for port-based Network Access Control (PNAC) that provides an authentication mechanism to devices wishing to attach to a LAN or WLAN.

The foundational framework that prevents unauthenticated devices from passing traffic on the enterprise network.

NDES (Network Device Enrollment Service)

A Microsoft Windows Server role that acts as a bridge, allowing devices without domain credentials to obtain certificates via SCEP.

A required infrastructure component when implementing on-premises SCEP certificate deployment.

PKCS (Public Key Cryptography Standards)

A set of standards where both the public and private keys are generated by the Certificate Authority and then securely delivered to the endpoint.

Often used for S/MIME email encryption, but less ideal for WiFi due to the network transmission of the private key.

CRL (Certificate Revocation List)

A list published by the Certificate Authority containing the serial numbers of certificates that have been revoked prior to their scheduled expiration date.

RADIUS servers must check this list to ensure compromised or lost devices are denied network access.

RADIUS (Remote Authentication Dial-In User Service)

A networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA) management for users who connect and use a network service.

The server that validates the client certificate during the EAP-TLS handshake.

VLAN (Virtual Local Area Network)

A logical subnetwork that groups a collection of devices from different physical LANs.

Used to enforce strict network segmentation between Corporate, BYOD, and Guest devices.

Ejemplos prácticos

A 400-room hotel needs to secure its staff WiFi network for 150 employees bringing their own smartphones, replacing an old WPA2-PSK network.

The hotel deploys a cloud-based MDM (like Microsoft Intune). They broadcast a provisioning SSID that directs users to a captive portal. The portal prompts users to enroll their device in the MDM. Once enrolled, the MDM pushes a Trusted Root profile, a SCEP profile, and an 802.1X WiFi profile. The device silently generates a key pair, requests a certificate via the SCEP URL, and connects to the secure BYOD SSID using EAP-TLS. The provisioning SSID is then forgotten.

Comentario del examinador: This approach works because it eliminates the shared password entirely. By using SCEP, the private key remains on the employee's personal device, satisfying privacy concerns while cryptographically verifying identity to the RADIUS server.

A retail chain with 50 locations is experiencing mass authentication failures after migrating from PEAP to EAP-TLS using SCEP.

The IT team audits the RADIUS server logs and discovers that the CRL Distribution Point (CDP) is unreachable from the RADIUS server. Because strict CRL checking is enabled, the RADIUS server rejects all connection attempts when it cannot verify the revocation status. The team resolves this by publishing the CRL to a highly available internal web server and updating the CDP extension in the CA template.

Comentario del examinador: This highlights a critical dependency in certificate-based authentication. While EAP-TLS provides superior security, it requires the underlying PKI infrastructure to be highly available. If the RADIUS server cannot check the CRL, it must fail closed to maintain security.

Preguntas de práctica

Q1. You are deploying Intune WiFi profiles for 802.1X. The devices receive the SCEP certificate successfully, but the WiFi profile fails to apply. What is the most likely cause?

Sugerencia: Consider how Intune resolves dependencies between profiles.

Ver respuesta modelo

The most likely cause is a group targeting mismatch. The Trusted Root, SCEP, and WiFi profiles must all be assigned to the exact same Azure AD group (either all Users or all Devices). If assignments differ, Intune cannot resolve the dependency chain.

Q2. A hospital IT director wants to use PKCS instead of SCEP for their BYOD WiFi deployment because it requires less on-premises infrastructure. What security risk should you highlight?

Sugerencia: Think about where the private key is generated.

Ver respuesta modelo

You should highlight that with PKCS, the private key is generated centrally by the CA and transmitted over the network to the device. For network authentication, SCEP is strongly recommended because the private key is generated locally on the device and never leaves the secure enclave.

Q3. During an EAP-TLS handshake, the client device rejects the connection to the RADIUS server, preventing a potential evil twin attack. Which configuration setting enables this protection?

Sugerencia: What does the client check during mutual authentication?

Ver respuesta modelo

Enforcing server certificate validation on the client supplicant enables this protection. The MDM-deployed WiFi profile must specify the trusted CA and the expected RADIUS server name, ensuring the device only connects to the legitimate corporate RADIUS server.

Continúe leyendo esta serie

Cómo configurar un Captive Portal en Starlink: guía para establecimientos remotos y marítimos

Esta guía detalla cómo omitir el hardware nativo de Starlink e integrar un Captive Portal gestionado en la nube utilizando equipos de enrutamiento empresariales. Aprenderá a superar la limitación de CGNAT, aplicar la segmentación de VLAN, gestionar las limitaciones de ancho de banda satelital y garantizar el cumplimiento normativo.

Leer la guía →

Hotel Guest WiFi Management: Integrating PMS, Portals, and Brand Standards

Esta guía técnica detalla cómo diseñar redes WiFi hoteleras de nivel empresarial, centrándose en la segmentación de VLAN, la integración de PMS para la gestión automatizada de sesiones y la optimización del Captive Portal para la captura de datos de conformidad con el GDPR.

Leer la guía →

Cómo optimizar los captive portals para una máxima seguridad de red y conversión de usuarios

Esta guía proporciona un esquema técnico completo para optimizar los captive portals en entornos empresariales, abarcando la arquitectura de segmentación de red, la selección del método de autenticación, el diseño de consentimiento conforme a la GDPR y la optimización de la conversión. Está dirigida a responsables de TI, arquitectos de red y CTO de hoteles, cadenas de tiendas, estadios y organizaciones del sector público que necesitan equilibrar la seguridad de la red con la captura de datos de primera mano. Purple opera la infraestructura de captive portals en más de 80.000 establecimientos con 440 millones de inicios de sesión en 2024, y los marcos de trabajo aquí presentados reflejan esa experiencia operativa.

Leer la guía →