Configure Wi-Fi with ONC
Use this guide for personal Wi-Fi, PEAP/MSCHAPv2 enterprise Wi-Fi, and certificate-based EAP-TLS. Publish through Business+ → Network Configuration after following the pilot workflow in Configure Network Policies.
Information to collect
| Network type | Required information |
|---|---|
| WPA/WPA2/WPA3 personal | SSID, passphrase, hidden/broadcast state, auto-connect decision |
| PEAP/MSCHAPv2 | SSID, outer/inner EAP methods, identity format, password source, server CA requirements |
| EAP-TLS | SSID, client certificate source or pattern, server CA, identity format |
WPA personal network
{
"Type": "UnencryptedConfiguration",
"NetworkConfigurations": [
{
"GUID": "{wifi-company-psk}",
"Name": "Company Wi-Fi",
"Type": "WiFi",
"WiFi": {
"AutoConnect": true,
"HiddenSSID": false,
"SSID": "Company_WiFi",
"Security": "WPA-PSK",
"Passphrase": "replace-with-managed-secret"
}
}
]
}
Use WPA-PSK for the broad WPA personal class. The full schema also lists
version-specific values such as WPA2, WPA2-WPA3, and WPA3. Confirm device
and access-point compatibility before narrowing the value.
PEAP with MSCHAPv2
The Management Cloud example uses ${LOGIN_EMAIL} for the signed-in user's
identity and ${PASSWORD} for the user's password:
{
"Type": "UnencryptedConfiguration",
"NetworkConfigurations": [
{
"GUID": "{wifi-company-peap}",
"Name": "Company 802.1X",
"Type": "WiFi",
"WiFi": {
"AutoConnect": true,
"SSID": "Company_8021X",
"Security": "WPA2-Enterprise",
"EAP": {
"Outer": "PEAP",
"Inner": "MSCHAPv2",
"Identity": "${LOGIN_EMAIL}",
"Password": "${PASSWORD}",
"SaveCredentials": true,
"UseSystemCAs": true
}
}
}
]
}
${PASSWORD} must be the complete field value to be substituted. If your
RADIUS identity uses only the part before @, use ${LOGIN_ID}. Do not copy a
real password into the JSON example.
EAP-TLS
EAP-TLS requires a client certificate and normally a server CA. Certificate selection can use a direct reference or a certificate pattern. A typical network shape is:
{
"Type": "UnencryptedConfiguration",
"NetworkConfigurations": [
{
"GUID": "{wifi-company-eap-tls}",
"Name": "Company EAP-TLS",
"Type": "WiFi",
"WiFi": {
"AutoConnect": true,
"SSID": "Company_EAP_TLS",
"Security": "WPA-EAP",
"EAP": {
"Outer": "EAP-TLS",
"ClientCertType": "Pattern",
"ClientCertPattern": {
"IssuerCARef": [
"{company-root-ca}"
]
},
"ServerCARef": "{company-root-ca}",
"UseSystemCAs": true
}
}
}
],
"Certificates": [
{
"GUID": "{company-root-ca}",
"Type": "Authority",
"TrustBits": [
"Web"
],
"X509": "replace-with-PEM-certificate-data"
}
]
}
Treat this as a structure example. Match the certificate pattern, trust model, and certificate data format to your PKI. The referenced certificate must be in the same ONC document.
Hidden networks and auto-connect
- Set
"HiddenSSID": trueonly when the access point does not broadcast the SSID. - Set
"AutoConnect": trueonly for networks devices should join automatically. - A hidden SSID is not a security control. Use appropriate authentication and encryption.
- Management Cloud applies these restrictions after sign-in. Test first-boot and enrolment connectivity separately.
Verify
- Sign in on a pilot device.
- Confirm the managed SSID appears and the expected source is policy.
- Connect and test DHCP, DNS, internet, and internal resources.
- For PEAP, confirm the expanded identity and RADIUS result.
- For EAP-TLS, confirm the selected client certificate and server CA.
- Restart and test again.
If the network does not connect, use Troubleshoot Managed Networks.
What's next
- Configure network policies, validate and publish ONC safely.
- Manage certificates, prepare trust anchors and client certificates.
- Troubleshoot managed networks, diagnose policy and connection failures.
- ONC reference, look up schema fields and accepted values.