Create a Wi-Fi Profile Library Item
To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the Library Overview article.Navigate to Library
Select Wi-Fi
Enter Name
Select Platforms
Assign to Blueprints
General Settings
- Apple
- Windows
Specify SSID
Configure auto join
Set hidden network (if needed)
Configure MAC address randomization
Enable IPv6 (optional)
Disable captive network detection (optional)
Authentication
- Apple
- Windows
None
Use the None authentication type when no password is necessary to join the network. If a network with the specified SSID is available and does not require authentication, the device will attempt to join it.- No password is required.
- Devices automatically connect if the SSID is available.
Pre-Shared Key (PSK)
PSK authentication is commonly used in home and small business environments. Anyone who has the network’s shared password can join it.Select security type
Enter network password
Enterprise (802.1X EAP)
Enterprise authentication uses 802.1X to provide more secure authentication options when connecting to Wi-Fi networks. Enterprise authentication types include:- Dynamic WEP
- WPA Enterprise
- WPA2 Enterprise
- WPA3 Enterprise
- Identity certificates (AD CS, SCEP, or PKCS #12)
- Trusted server certificates
- User authentication (username/password, smartcard, or certificates)
Select authentication type
Configure login window settings (macOS)
Select EAP types
Configure an Identity Certificate
You can configure an identity certificate using AD CS, SCEP, or by uploading a PKCS #12 file. For instructions on configuring identity certificates, see our Using Identity Certificates for 802.1X Authentication support article.If you are using AD CS, complete AD CS Integration: Overview and AD CS Integration: Configure the Integration first.Proxy
Enable Proxy management
Configure Automatic proxy
Configure PAC fallback (optional)
Configure Manual proxy
Fast Lane Marking
Disable Fast Lane (optional)
Enable Fast Lane for specific apps
Add applications to allow list
Search apps by name
Add apps by Bundle ID
Configure Bundle ID details
Complete Fast Lane configuration
Certificate Trust Settings
Specifying trusted certificates in the Wi-Fi Library Item is not recommended. If certificates are renewed or changed, you will need to redeploy the entire Wi-Fi profile, potentially causing devices to disconnect from the Wi-Fi network. Instead, install the trusted certificate chain for your RADIUS server(s) using a separate Certificates Library item. Then specify the name of those certificates in the Wi-Fi Library item under Specify server certificate names. See Apple Platform Deployment for more information. Most enterprise Wi-Fi environments require that devices trust the 802.1X authentication server(s), typically a Remote Access Dial-In User Server (RADIUS). The Certificate trust settings allow you to configure which certificates presented by the server devices will trust. If a device does not trust the authentication server(s), the user will be prompted to trust it.Specify trusted certificates (optional)
Specify server certificate names (optional)