# Wi-Fi
Last updated: August 14, 2026
This page explains how to configure the Windows Wi-Fi Profile in MDM for Windows phones running Windows 8.1 and later, and Surface Hubs running Windows 10 or above Team OS. It covers key profile settings including wireless network identification, hidden network configuration, automatic network joining, and security types such as None, WPA2 PSK, and 802.1x EAP. The page also details EAP methods (PEAP and TLS), CA certificate setup, and proxy configuration options (manual or automatic) for managed Windows devices.
You can configure the Wi-Fi settings and proxy for Windows phones running on **Windows 8.1 and later versions.** Wi-Fi profile is also supported for **Surface Hubs running Windows 10 or above Team OS**.
## Profile Description
| Profile Specification | Description |
|---|---|
| Wireless Network identification | Specify the name for the Wi-Fi. |
| Hidden Network | Configure your Wi-Fi profile as a hidden network. This will hide the Wi-Fi network from unauthorized devices. Only devices to which the profile is associated to, will be able to access the Wi-Fi configured via MDM. |
| Automatically join network | Specify, if you wanted to allow the devices to automatically join the above mentioned network when it is reachable. |
| Security type | Choose one of the following security types:
**>** None: You can choose this if you do not want to secure the Wi-Fi connection. Devices then connect to the Wi-Fi without prompting for password.
**>** WPA2 PSK: If this is chosen, only authenticated users are allowed to connect the network.
**>** 802.1x EAP: This is considered to be the most secure type of connection. 802.1x uses an authentication server to validate the users before establishing the connection. |
| EAP method | Specify the EAP method to be used. You can choose between PEAP and TLS. |
| Phase 2 Authentication **(Can be configured only if EAP method is selected as PEAP** | By default, **MSCHAPv2** is the Phase 2 Authentication used. |
| CA Certificate | You can select or upload a CA certificate to authenticate the connection. **In case the EAP method selected is PEAP, provide the certificate of the server authenticating the Wi-Fi connection. If it is TLS, then provide the certificate of the CA, which has issued the client certificate to be used for TLS. Also, ensure the User Principal Name (UPN) present in the client certificate must be the user name**. |
| **Configure Proxy** | |
| Proxy Settings | You have to specify the type of proxy as manual or automatic. If you specify the type as Automatic, you have to specify the Server URL. If you specify the type as Manual, you have to provide the server name and port details. |
## Frequently Asked Questions
**Which Windows devices support the Wi-Fi profile?**
The Wi-Fi profile is supported on Windows phones running Windows 8.1 and later versions, as well as Surface Hubs running Windows 10 or above Team OS.
**What's the most secure Wi-Fi security type I can configure?**
802.1x EAP is considered the most secure connection type, since it uses an authentication server to validate users before establishing the connection.
**Can I hide the corporate Wi-Fi network from unauthorized devices?**
Yes, configure the Wi-Fi profile as a Hidden Network so only devices to which the profile is associated can access the network configured via MDM.