Skip to main content

Configure network policies

FydeOS Management Cloud deploys managed network settings as Open Network Configuration (ONC) JSON. Use ONC when devices need a preconfigured Wi-Fi, Ethernet, VPN, proxy, DNS, or certificate-backed connection.

ONC Editor

Before you begin​

  • Create a pilot organisational unit and move one representative device into it.
  • Keep a working fallback network available during testing.
  • Collect the SSID, security type, EAP method, identity format, VPN or proxy details, and certificate requirements.
  • Decide whether the connection is for signed-in users or for another device stage. The console currently states that network restrictions apply only after users sign in.
  • Store passphrases and private keys using your organisation's approved secret process. Do not place production credentials in screenshots or tickets.

Choose the right configuration​

RequirementStart here
WPA/WPA2/WPA3 personal Wi-FiConfigure Wi-Fi with ONC
PEAP/MSCHAPv2 or EAP-TLS Wi-FiConfigure Wi-Fi with ONC
Ethernet, static IP, VPN, or per-network proxyConfigure Ethernet, VPN, and Proxy
User/device placeholders and reusable JSONONC Variables and Examples
Certificate upload and renewalManage Certificates
A managed network does not workTroubleshoot Managed Networks

Publish an ONC change​

  1. Open Business+ → Network Configuration.
  2. Select the pilot Organisational Unit.
  3. Copy the current ONC to your change record before editing it.
  4. Edit the complete JSON document in ONC Editor. The top-level type for a normal policy is UnencryptedConfiguration.
  5. Use the formatter button and check brackets, commas, quotes, and field types.
  6. Confirm that every network and certificate has a stable, unique GUID.
  7. Review the applied or inherited state shown below the editor.
  8. Save the policy if the page presents a save action. Do not switch units until the change is complete.
Sign-in and enrolment connectivity

Management Cloud explains that its network restrictions apply after users log in. Do not assume this policy will provide first-boot or enrolment connectivity. Keep an enrolment network available until a pilot has completed enrolment, sign-in, policy sync, and restart testing.

How ONC updates work​

  • A GUID identifies one network or certificate. Keep it unchanged when updating that same object.
  • Use a different GUID for every distinct object, even when names are similar.
  • Set "Remove": true and provide only the existing GUID to remove an imported network or certificate.
  • Any certificate referenced by GUID must be included in the same ONC document.
  • Replacing the editor content with {} removes the definitions from that policy document. Treat this as a production change, not as a harmless reset.
  • Child organisational units can inherit a parent configuration. Check the selected unit and the inheritance state before diagnosing the JSON.

Pilot and verify​

  1. Apply the configuration to a pilot unit.
  2. Sign in on the pilot device and allow time for policy sync.
  3. Confirm that the expected network appears and connects automatically only when intended.
  4. Test IP assignment, DNS, captive portal handling, proxy routing, internal resources, and public internet access.
  5. For enterprise authentication, verify the identity value and server certificate chain.
  6. Restart and test sign-in again.
  7. Test rollback by restoring the saved previous JSON.
  8. Expand to production units in stages.

For every field and supported object type, use the Open Network Configuration reference.

What's next​