Skip to content
← Security & Infrastructure

Enterprise 802.1X / EAP-TLS Deployment

Certificate-based WPA2-Enterprise Wi-Fi across 30 sites, with RADIUS/NPS hosted in Azure.

Category
Security & Infrastructure
Type
Production work

Designed and rolled out certificate-based WPA2-Enterprise Wi-Fi across 30 sites: ADCS certificate autoenrollment via GPO, NPS/RADIUS policy on Azure-hosted domain controllers, and CRL/CDP reachability validation across split-VPN topologies.

The result is centralized, certificate-based network access control — devices authenticate as themselves rather than sharing a pre-shared key, and access can be revoked at the certificate rather than by rotating a password across thirty sites.

The validation work mattered as much as the rollout. In split-VPN topologies a client that cannot reach the CRL distribution point fails authentication in ways that look like a radio problem, so reachability was proven per site rather than assumed.

Built with

  • 802.1X
  • EAP-TLS
  • RADIUS/NPS
  • Microsoft Azure
  • ADCS
  • Group Policy

Client work — no public link, and no client names or specifics beyond what is already on the resume.