Forum Discussion

mmiadmin's avatar
mmiadmin
Copper Contributor
Jul 20, 2022
Solved

Certificates in Intune

What are these certificates that gets installed while installing the Intune connector and what kind of certificates are needed? 

 

I am not sure which certificates needs to be installed as well as whether it is PKCS or SCEP. Can someone give a clear overview of why this is needed and what it does and which one to install?

 

If you’ll use SCEP with a Microsoft Certification Authority (CA), confirm that the Network Device Enrollment Service (NDES) role is installed.

 

  • SCEP: Select this option to enable certificate delivery to devices from a Microsoft Active Directory Certification Authority using the SCEP protocol. Devices that submit a certificate request will generate a private/public key pair and submit only the public key as part of that request.

  • PKCS: Select this option to enable certificate delivery to devices from a Microsoft Active Directory Certification Authority in PKCS #12 format. Ensure you’ve set up all the necessary prerequisites.

  • PKCS imported certificates: Select this option to enable certificate delivery to devices for pfx certificates that you've imported to Intune. Ensure you’ve set up all the necessary prerequisites.

  • Certificate revocation: Select this option to enable automatic certificate revocation for certificates issued from a Microsoft Active Directory Certification Authority.

 

7 Replies

    • mmiadmin's avatar
      mmiadmin
      Copper Contributor
      Thank you. I have done this in Citrix Endpoint Management, but not in Intune MDM. So, if this is what its function is to enroll the Android or IOS devices into Intune, then I think that makes sense. But, which one is for what is there any idea?

      Thanks again!
      • It's not needed for enrollment itself, just for things like VPN or WiFi based on certificate authentication.