Skip to main content

Configure Wi-Fi with ONC

Use this guide for personal Wi-Fi, PEAP/MSCHAPv2 enterprise Wi-Fi, and certificate-based EAP-TLS. Publish through Business+ → Network Configuration after following the pilot workflow in Configure Network Policies.

Information to collect​

Network typeRequired information
WPA/WPA2/WPA3 personalSSID, passphrase, hidden/broadcast state, auto-connect decision
PEAP/MSCHAPv2SSID, outer/inner EAP methods, identity format, password source, server CA requirements
EAP-TLSSSID, client certificate source or pattern, server CA, identity format

WPA personal network​

{
"Type": "UnencryptedConfiguration",
"NetworkConfigurations": [
{
"GUID": "{wifi-company-psk}",
"Name": "Company Wi-Fi",
"Type": "WiFi",
"WiFi": {
"AutoConnect": true,
"HiddenSSID": false,
"SSID": "Company_WiFi",
"Security": "WPA-PSK",
"Passphrase": "replace-with-managed-secret"
}
}
]
}

Use WPA-PSK for the broad WPA personal class. The full schema also lists version-specific values such as WPA2, WPA2-WPA3, and WPA3. Confirm device and access-point compatibility before narrowing the value.

PEAP with MSCHAPv2​

The Management Cloud example uses ${LOGIN_EMAIL} for the signed-in user's identity and ${PASSWORD} for the user's password:

{
"Type": "UnencryptedConfiguration",
"NetworkConfigurations": [
{
"GUID": "{wifi-company-peap}",
"Name": "Company 802.1X",
"Type": "WiFi",
"WiFi": {
"AutoConnect": true,
"SSID": "Company_8021X",
"Security": "WPA2-Enterprise",
"EAP": {
"Outer": "PEAP",
"Inner": "MSCHAPv2",
"Identity": "${LOGIN_EMAIL}",
"Password": "${PASSWORD}",
"SaveCredentials": true,
"UseSystemCAs": true
}
}
}
]
}

${PASSWORD} must be the complete field value to be substituted. If your RADIUS identity uses only the part before @, use ${LOGIN_ID}. Do not copy a real password into the JSON example.

EAP-TLS​

EAP-TLS requires a client certificate and normally a server CA. Certificate selection can use a direct reference or a certificate pattern. A typical network shape is:

{
"Type": "UnencryptedConfiguration",
"NetworkConfigurations": [
{
"GUID": "{wifi-company-eap-tls}",
"Name": "Company EAP-TLS",
"Type": "WiFi",
"WiFi": {
"AutoConnect": true,
"SSID": "Company_EAP_TLS",
"Security": "WPA-EAP",
"EAP": {
"Outer": "EAP-TLS",
"ClientCertType": "Pattern",
"ClientCertPattern": {
"IssuerCARef": [
"{company-root-ca}"
]
},
"ServerCARef": "{company-root-ca}",
"UseSystemCAs": true
}
}
}
],
"Certificates": [
{
"GUID": "{company-root-ca}",
"Type": "Authority",
"TrustBits": [
"Web"
],
"X509": "replace-with-PEM-certificate-data"
}
]
}

Treat this as a structure example. Match the certificate pattern, trust model, and certificate data format to your PKI. The referenced certificate must be in the same ONC document.

Hidden networks and auto-connect​

  • Set "HiddenSSID": true only when the access point does not broadcast the SSID.
  • Set "AutoConnect": true only for networks devices should join automatically.
  • A hidden SSID is not a security control. Use appropriate authentication and encryption.
  • Management Cloud applies these restrictions after sign-in. Test first-boot and enrolment connectivity separately.

Verify​

  1. Sign in on a pilot device.
  2. Confirm the managed SSID appears and the expected source is policy.
  3. Connect and test DHCP, DNS, internet, and internal resources.
  4. For PEAP, confirm the expanded identity and RADIUS result.
  5. For EAP-TLS, confirm the selected client certificate and server CA.
  6. Restart and test again.

If the network does not connect, use Troubleshoot Managed Networks.

What's next​