Sunday, March 21, 2021

How are you handling Wi-Fi authentication for environments without an on-prem NPS server or Certificate Authority?

Title. There are some customers that are excellent fits for zero servers and all InTune in other areas, but this is a problem that we've run up against.

SecureW2 seems to be able to do it but I don't know their pricing and they've put it behind a "let's setup a quick call with a salesperson" wall so no thanks.

Azure AD DS and some NPS servers chilling in Azure is a method, but as an MSP I'm not sure how or if that could be mutli-tenant capable.

Pushing a long PSK-based profile via InTune isn't a great option because a simple one liner NETSH command can pull the PSK in 1 second.

Ideally, I'd love something that can replicate AD CS Automatic certificate enrollment + automatic Wi-Fi network join. The second part of that is simple enough to do with InTune, and InTune can even point devices as a SCEP-capable server.

Thoughts?



No comments:

Post a Comment