Explore Our Microsoft Intune Training →
In this blog post, we will walk you through deploying SCEP (Simple Certificate Enrollment Protocol) certificates for Wi-Fi and VPN authentication in Microsoft Intune. This process involves creating trusted root and SCEP certificate profiles, linking them to respective Wi-Fi and VPN profiles, and troubleshooting any failures that may occur.
How SCEP Certificate Profiles Work
SCEP certificates are generated by a Certificate Authority (CA) using the Simple Certificate Enrollment Protocol. Intune supports both Network Device Enrollment Service (NDES) and Cloud PKI for generating SCEP certificates.
Prerequisites
To deploy SCEP certificate profiles, you need to have either NDES or Cloud PKI set up. Ensure that the root certificate of your CA is trusted in the device before proceeding with the SCEP deployment.
Creating Trusted Root and SCEP Certificate Profiles
1. Create a Trusted Root Certificate Profile.
– In the Intune console, navigate to Tenant administration > Connectors and tokens > PKI > Certificates > Root certificates.
– Click on Add, choose Root certificate, and follow the on-screen instructions.
2. Create an SCEP Profile.
– Navigate to Tenant administration > Connectors and tokens > Certificates > SCEP profiles.
– Click on Add, choose SCEP profile, and follow the instructions.
Note: In the SCEP profile, specify your CA’s URL, key pair, and other necessary details. If you are using NDES, ensure that the NDES connector is configured correctly.
Linking Certificate Profiles to Wi-Fi and VPN Profiles
1. Navigate to Devices > Configuration profiles.
– Click on Create profile, choose Windows 10 and later (VPN) or Windows 10 and later (Wi-Fi), depending on your requirement.
– Assign the created SCEP certificate profile to the Wi-Fi or VPN configuration profile.
2. Distribute the newly created configuration profile to device groups.
Troubleshooting SCEP Certificate Delivery Failures
1. Check the NDES and IME logs for delivery failure reasons.
– For NDES, go to Tenant administration > Connectors and tokens > PKI > NDES connector settings.
– Click on the NDES connector, and under the Logs section, find the download logs.
2. If you are using Cloud PKI, check the Intune Diagnostics and Log Collection feature to gather logs remotely from managed devices.
– In the Intune console, go to Tenant administration > Device configuration > Troubleshooting > Diagnostics and log collection.
Conclusion
Deploying SCEP certificates for Wi-Fi and VPN authentication in Microsoft Intune ensures a secure network environment. By following this guide, you will be able to set up the necessary certificate profiles and link them to Wi-Fi or VPN profiles without any hassle.
Ready to master Microsoft Intune?
Explore our comprehensive Microsoft Intune Training courses and take your skills to the next level.
Explore Our Microsoft Intune Training →
Written by Mohammed Akhter
Founder of ITP Training. 50,000+ students trained across 30+ countries in Microsoft endpoint and cloud security. Learn more →
