Secure Network Access Bundle
Certificate-based Wi-Fi, LAN, and VPN authentication from the team that builds both SCEPman and RADIUSaaS
Managing on-premises NDES servers and RADIUS appliances is painful, fragile, and impossible to scale. Our bundle takes the pain out of certificate and network access management – so your team can focus on real priorities.
With this bundled solution, you can:
Issue and renew certificates automatically from Microsoft Intune, Jamf, or other MDMs
Replace NDES for Intune with a modern SCEP service running entirely in the cloud
Deliver 802.1X / EAP-TLS Wi-Fi and VPN authentication through a fully managed cloud RADIUS service.
Provide employees and devices with passwordless access in minutes, not months
One subscription, no servers to patch, and always up to date.
SaaS or Enterprise: You decide
Both bundles pair a cloud-native certificate authority (SCEPman) with a cloud-native RADIUS service (RADIUSaaS) for certificate-based network authentication. The difference is where SCEPman runs and who operates it.
NewSaaS Bundle
Zero infrastructure. Zero headaches.
- SCEPman runs in our data centers
- No Azure tenant required
- All-inclusive pricing, no infrastructure costs
- We handle provisioning, updates, and availability
NewEnterprise Bundle
Full control. Your Azure tenant. Your rules.
- SCEPman runs in your Azure tenant
- You pay Azure infrastructure cost for SCEPman
- You handle the provisioning, updates, and availability
- Features for advanced use cases
What you get
You will be using a bundled, fully integrated solution consisting of SCEPman and RADIUSaaS, both developed by glueckkanja:
SCEPman: Cloud Certificate Authority
- Automated X.509 certificate enrollment via SCEP
- Works with Intune, Jamf, Kandji, Mosyle, Google Workspace, SOTI
- Real-time certificate validation via OCSP
- Certificate Master for server, network device, and IoT certificates
- SCEPman Connection for automatic RADIUS server certificate management
- Risk-based validation: object-binding ties certificates to Entra ID / Jamf objects — disable the user or device, revoke the certificate instantly
RADIUSaaS: Cloud RADIUS Service
- Managed cloud RADIUS for Wi-Fi, LAN, and VPN
- EAP-TLS certificate-based authentication
- Username/password authentication for legacy devices and IoT
- Self-service portal for guest and BYOD access
- Compatible with all major network vendors (Cisco, Aruba, Extreme, Juniper, Fortinet, Meraki, UniFi, and more)
- RadSec support for encrypted RADIUS communication
Built and Operated by One Team
- SCEPman and RADIUSaaS are built by glueckkanja — one vendor, one support contact
- ISO 27001-certified operations
- EU, US, UK, and Australia data center options
- Tightest integration on the market — including automatic RADIUS server certificate management via SCEPman Connection
Why Admins Choose This Solution
| Challenge | How we solve it |
|---|---|
| Running NDES servers | Replaced by cloud-native SCEP server (SCEPman) in your Azure tenant |
| Managing RADIUS appliances | Offloaded to fully managed cloud RADIUS (RADIUSaaS) |
| Weak Wi-Fi security with passwords | Enforce 802.1X / EAP-TLS certificate-based Wi-Fi and VPN for every device |
| User onboarding complexity | Automated certificate profiles pushed from Intune/Jamf — no manual setup |
| Scaling beyond a single office | Global availability with Azure redundancy and 25% cost savings compared to standalone solutions |
Why Zero Infrastructure Matters
Every Azure resource you operate is a resource you must provision, secure, monitor, patch, and pay for. The SCEPman SaaS edition removes all of that. No App Service Plans. No Key Vaults. No Storage Accounts. No ARM templates. No Terraform. No Azure subscription required at all. glueckkanja runs SCEPman in its own data centers — you configure your MDM profiles and network equipment, and you're done.
Works with any ecosystem
- SCEPman SaaS does not require an Azure tenant
- Certificate-based network access for Jamf Pro, Google Workspace, Kandji, or any MDM
- Not limited to the Microsoft ecosystem
- Bring Your Own Key Vault (BYOK) option for key sovereignty without infrastructure overhead
All-inclusive pricing
- The SaaS bundle subscription fee is the total cost
- No Azure consumption charges, no hidden infrastructure bills
- The SaaS bundle is often the more cost-effective choice
Fastest time to first certificate
- glueckkanja handles the initial RADIUSaaS & SCEPman provisioning
- No ARM template deployments, no Azure resource group planning, no Key Vault access policies
- From decision to first authenticated device in a day, not a quarter
Operated by the team that built it
- Built, deployed, and operated by the same glueckkanja engineering team
- Updates, patches, scaling, and availability — all handled
- Your IT team focuses on security policy and endpoint configuration, not infrastructure
Get Started with the SaaS Bundle in Three Steps
- SubscribeSubscribeChoose the RADIUSaaS & SCEPman SaaS Bundle. glueckkanja provisions your RADIUSaaS & SCEPman SaaS instance.
- ConfigureConfigureSet up your SCEP profiles in Intune, Jamf, or your MDM of choice. Configure RADIUSaaS and connect your network equipment.
- Go LiveGo LiveDevices receive certificates automatically. RADIUSaaS enforces them at every network authentication event. Done.
Get Started with the Enterprise Bundle in Four Steps
- SubscribeSubscribeChoose the RADIUSaaS & SCEPman Enterprise Bundle. glueckkanja provisions your RADIUSaaS instance.
- DeployDeployDeploy SCEPman into your Azure tenant using ARM templates or Terraform. Configure Key Vault and App Service resources.
- ConfigureConfigureSet up your SCEP profiles in Intune or Jamf. Configure RADIUSaaS and connect your network equipment.
- Go LiveGo LiveDevices receive certificates automatically. RADIUSaaS enforces them at every network authentication event. Done.
Frequently Asked Questions
Ready to Eliminate Wi-Fi Passwords?
Start with a free trial — no commitment, no credit card required. Choose the edition that fits your environment.
Try it out for free now!