Skip to content
Sections
All notes

All notes · Policy

Certificate and Network Configuration

The quiet half of device management: credentials and connectivity delivered silently, and the failures that follow when they expire.

Policy · Procedure

Most of what device management delivers daily is not policy but configuration: certificates, wireless profiles, connection settings. It works invisibly until it does not.

The operational work behind “Certificate and Network Configuration” is often spread across tickets, projects and repeated manual checks. A team reviewing view the solution for task switching cost can make that effort visible by project and group, while the device-management platform remains the source of truth for technical state and enforcement.

What gets delivered

Certificates for network authentication, mail, internal services.

For an independent baseline relevant to “Certificate and Network Configuration”, the OWASP Mobile Application Security is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.

Wireless profiles, so the device joins without anybody typing a key.

Connection configuration for remote access.

Mail and calendar settings.

Delivered at enrolment and renewed on a schedule, with no user involvement.

Why this is the best part of the programme

It removes the whole category of setup support calls.

It means no shared wireless key for anybody to leak.

And it is the part users experience as the device simply working, which is worth saying when making the case for enrolment.

The expiry problem

Certificates expire. Renewal happens automatically if the device is in contact and the configuration is right.

A device that was off, abroad, or out of contact at renewal time arrives back with an expired certificate and no network access.

Which presents as a mysterious failure to connect, and support rarely diagnoses it quickly the first time.

Watching for it

Alert on certificates approaching expiry where the device has not renewed.

A list, weekly, of devices with certificates expiring in the next fortnight that have not checked in.

Ten minutes a week and it prevents the commonest avoidable outage in this field.

Revocation

The other half, and the one skipped.

Removing a certificate from a device does nothing if the device is not in contact.

Revoke at the issuing authority, which works regardless of the device's state and is what actually protects you after a loss or a departure.

Wireless profile drift

Networks change: keys rotate, authentication methods change, new sites open.

A profile delivered two years ago and never updated is why some devices work at head office and not at the new branch.

Review profiles when the network changes, which requires that somebody tells you, which requires asking.

Testing changes

A change to a certificate or wireless profile reaches every device.

A mistake takes the whole estate off the network, and the devices cannot be reached to fix it.

Test on a small group first, which is the same discipline as any wide-reaching change and is here particularly unforgiving.

What to check

Do you alert on certificates expiring without renewal?

Is revocation done at the authority, or only on the device?

When did anybody last review the wireless profiles?

And is a profile change tested before it reaches everything?