Enterprise 802.1X / EAP-TLS Deployment
Certificate-based WPA2-Enterprise Wi-Fi across 30 sites, with RADIUS/NPS hosted in Azure.
- Category
- Security & Infrastructure
- Type
- Production work
Designed and rolled out certificate-based WPA2-Enterprise Wi-Fi across 30 sites: ADCS certificate autoenrollment via GPO, NPS/RADIUS policy on Azure-hosted domain controllers, and CRL/CDP reachability validation across split-VPN topologies.
The result is centralized, certificate-based network access control — devices authenticate as themselves rather than sharing a pre-shared key, and access can be revoked at the certificate rather than by rotating a password across thirty sites.
The validation work mattered as much as the rollout. In split-VPN topologies a client that cannot reach the CRL distribution point fails authentication in ways that look like a radio problem, so reachability was proven per site rather than assumed.
Built with
- 802.1X
- EAP-TLS
- RADIUS/NPS
- Microsoft Azure
- ADCS
- Group Policy
Client work — no public link, and no client names or specifics beyond what is already on the resume.