A practical guide to the industry-wide shift in trusted certificate authorities for EAP-TLS and how to avoid mass device disconnects in BYOD environments.
In 2026, organizations using RADIUS-based authentication (especially EAP-TLS for certificate-based Wi-Fi) face mandatory updates to the certificate authorities their infrastructure and client devices trust. For environments with thousands of personal devices, this creates a high-risk re-enrollment event. Many pure AAA deployments will struggle with the scale and user friction. Dedicated onboarding platforms that can push updated profiles over the public internet — combined with careful dual-trust planning — turn a potential crisis into a manageable project.
Universities, healthcare systems, and large enterprises should treat this as a 2025–2026 priority alongside any Wi-Fi 7 or zero-trust initiatives. The cost of poor planning is mass support tickets and lost productivity when devices suddenly lose network access.
Public and private certificate authorities periodically update their root and intermediate certificates. When a widely used CA root is scheduled for deprecation, RADIUS servers and the devices that connect to them must be updated to trust the replacement. In 2026, several major shifts in trusted CAs for 802.1X/RADIUS infrastructure are coming to a head.
Devices that were onboarded with profiles referencing the old chain will fail authentication after the cutover date unless their profiles are updated to include the new trust anchors.
High-level 2026 migration timeline — preparation in 2025 is critical for large BYOD environments.
Corporate-managed devices can often have new profiles pushed silently via MDM. Personal devices (the majority in universities and many enterprises) rely on self-service or one-time onboarding. If that onboarding was done against the old CA chain, those devices become "orphaned" after cutover.
How dedicated onboarding platforms (accessible over the internet) enable mass profile updates before cutover.
Platforms like Cisco ISE have native BYOD portals and certificate provisioning. However, they are often designed around on-campus or already-connected experiences. Re-enrolling tens of thousands of off-network personal devices through native tools at the last minute is operationally unrealistic for most organizations.
Without a dedicated layer that can deliver updated profiles over the public internet (before or after the cutover), IT teams are left with manual instructions, QR codes that only work on campus, or mass helpdesk queues.
A modern cloud onboarding + dynamic PKI layer can:
Inventory which CA roots are currently trusted in your RADIUS servers and embedded in existing device profiles. Identify the population of devices that will be affected.
Configure your RADIUS infrastructure to trust both the old and new CA chains during the transition window. Test thoroughly.
Leverage internet-reachable enrollment flows to deliver updated profiles. Prioritize high-churn populations (students, contractors). Monitor success rates in real time.
After the deadline, remove old trust where safe. Continue using the onboarding layer for ongoing new devices and future renewals.
Your ISE (or equivalent) continues to handle authentication and policy. The onboarding platform acts as the front-end enrollment and profile distribution engine. Coordinate certificate templates and revocation so both systems see the same identities.
If you have a large BYOD population or are already using (or considering) a dedicated onboarding platform alongside your AAA, now is the time to model the migration project. Request a consultation to review your current CA trust posture, device population, and tooling options for a low-drama 2026.