Intune WiFi certificates with cloud RADIUS
Intune delivers the certificate and the WiFi profile. Purple issues the certificate and runs the cloud RADIUS it authenticates against. Every managed device you issue arrives on the network with nothing for the person to do, and there is no certificate authority or RADIUS server for you to run.
How do you push WiFi certificates with Intune?
Intune sends each managed device a trusted root certificate, a SCEP profile that requests a client certificate, and a WiFi profile set to EAP-TLS. With Purple, the device requests its certificate from Purple and authenticates against Purple’s cloud RADIUS. Setup takes around 5 to 10 minutes, once, for the whole organisation.
Why Intune alone is not enough
Intune is the delivery mechanism. Certificate-based WiFi also needs a certificate authority to issue each device its certificate and a RADIUS server to check that certificate when the device joins. Building that yourself means a PKI, its revocation endpoints and a RADIUS service that trusts it.
Purple supplies both halves. The device picks up the Intune policy, asks Purple for a certificate carrying the user’s identity, and Purple checks your directory before issuing it, so only people who still work for you get one.
How it works with Purple
Set Purple up in Intune
Trust two certificates and add two profiles. Around 5 to 10 minutes, once, for the whole organisation.
The device asks for a certificate
It picks up the policy and calls Purple directly over SCEP, carrying the user’s identity.
Purple issues it
Checked against your directory first, so a certificate is only minted for someone still in it.
The device connects
It authenticates to Purple’s cloud RADIUS over WPA2 or WPA3-Enterprise. The person does nothing.
What is supported
- Delivery
- A certificate profile plus a WiFi profile, deployed over SCEP.
- Platforms
- Windows, macOS, iOS and Android devices managed by Intune.
- Certificate authority
- Purple issues the certificate. The private key is generated on the device and held in its secure hardware.
- Identity check
- A callback to your identity provider on every issue, so a certificate is only minted for someone still in your directory.
- Personal devices
- The same SSID and the same cloud RADIUS, with the certificate installed through the Purple app instead of Intune.
- Access points
- Any enterprise access point that speaks RADIUS, including Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. You reconfigure the SSID, not the hardware.
- Certification
- Purple is ISO 27001 certified, and GDPR and CCPA compliant.
What Purple does not do
- You cannot bring your own certificate authority. Purple’s RADIUS authenticates against Purple’s backend, so the certificate has to be one Purple issued.
- Purple does not replace Intune and does not read from it. It sees a device’s MAC address, serial number and certificate details, not its name, owner, compliance state or operating system.
- Purple does not check whether a device is patched or encrypted. Posture checking stays with your MDM.
- The directory sync runs roughly hourly, and revocation applies to the next authentication rather than cutting a live session.
Every statement above about what Purple does is taken from Certificate-based WiFi via MDM and Staff WiFi.
Guides for Intune WiFi authentication
The technical detail behind this page, including the routes that do not involve Purple.
How to use Microsoft Intune to push WiFi certificates to devices
Microsoft Intune WiFi certificate deployment via SCEP and PKCS
How to set up Azure Entra ID for WiFi authentication
What is cloud RADIUS?
How RADIUS as a service works and when it replaces an on-site server.
Enterprise WiFi security guide
802.1X, WPA3-Enterprise and certificate-based authentication, from first principles.
Other identity providers and device management
The same cloud RADIUS sits behind each of these. See the RADIUS-as-a-Service overview for the authentication flow, or compare cloud RADIUS providers.
Intune and cloud RADIUS: questions
How do you push WiFi certificates with Intune?
Intune sends each managed device a trusted root certificate, a SCEP profile that requests a client certificate, and a WiFi profile set to EAP-TLS. With Purple, the device requests its certificate from Purple and authenticates against Purple’s cloud RADIUS. Setup takes around 5 to 10 minutes, once, for the whole organisation.
Does the user have to do anything?
No. They log in to the laptop they were issued and it is on the WiFi. There is no app to install and no sign-in step on an Intune-managed device. The Purple app is the separate route for personal devices.
Can we use our own certificate authority or Microsoft Cloud PKI?
No. Purple’s RADIUS authenticates against Purple’s backend, so the certificate has to be one Purple issued. Most teams asking are trying to stop running certificate infrastructure, which this removes.
Which device management systems does Purple support besides Intune?
JumpCloud, IRU (formerly Kandji) and Jamf Pro. The mechanism is SCEP, an open standard, so other systems are likely to work, but Purple has not tested them.
Does Purple check Intune compliance before a device joins?
No. Purple does not read from Intune and does not check whether a device is patched or encrypted. Posture checking stays with your MDM, and Purple handles onboarding, certificate lifecycle and attribution.
Ultima revisione:
See Intune WiFi running on your own access points
Tell us your identity provider, device management and access point vendors, and we will show you the setup on a test tenant.
Speak to an expert
Tell us what you need and we'll be in touch.