Home
%3CLINGO-SUB%20id%3D%22lingo-sub-1025511%22%20slang%3D%22en-US%22%3ERe%3A%20Known%20Issue%20with%20SCEP%20profiles%20for%20Android%20Enterprise%20fully%20managed%20devices%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1025511%22%20slang%3D%22en-US%22%3E%3CP%3EGood%20to%20see%20this%20issue%20is%20acknowledged.%20We%20actually%20have%20it%20and%20were%20working%20with%20MS%20support%20for%20months%20to%20figure%20it%20out.%20In%20the%20end%20because%20of%203%20lines%20out%20of%20the%20Intune%20Device%20logs%20send%20to%20us%20by%20support%20we%20figured%20it%20out.%20Intune%20was%20actually%20taking%20the%20Display%20Name%20and%20using%20that%20as%20Common%20Name%20in%20the%20certificate%20request.%3C%2FP%3E%3CP%3EThis%20can%20fail%20early%20in%20the%20process%20if%20the%20Display%20Name%20has%20special%20characters%20in%20it.%20Or%20it%20succeeds%20and%20provides%20the%20certificate%20with%20a%20Common%20Name%20value%20that%20is%20wrong.%20(In%20our%20case%20the%20Display%20Name)%20Then%20when%20using%20the%20certificate%20for%20connecting%20to%20for%20example%20Wifi%20it%20will%20fail%20the%20authentication.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWorkaround%20for%20us%20was%20to%20use%20the%20exact%20same%20value%20for%20the%20Display%20Name%20and%20Common%20Name.%20But%20this%20is%20only%20feasible%20for%20some%20testing.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F226779%22%20target%3D%22_blank%22%3E%40Intune%20Support%20Team%3C%2FA%3E%26nbsp%3BWhat%20would%20have%20been%20helpful%20in%20finding%20this%20issue%20must%20quicker%20is%20to%20have%20access%20to%20the%20Intune%20Device%20logs.%20As%20a%20customer%20I%20noticed%20straight%20away%20that%20the%20common%20name%20value%20used%20in%20the%20certificate%20request%20was%20wrong.%20But%20this%20error%20message%20only%20showed%20up%20in%20the%20Device%20logs.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1030087%22%20slang%3D%22en-US%22%3ERe%3A%20Known%20Issue%20with%20SCEP%20profiles%20for%20Android%20Enterprise%20fully%20managed%20devices%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1030087%22%20slang%3D%22en-US%22%3EIs%20there%20any%20update%20or%20time%20frame%20on%20when%20the%20fix%20will%20be%20deployed%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1030218%22%20slang%3D%22en-US%22%3ERe%3A%20Known%20Issue%20with%20SCEP%20profiles%20for%20Android%20Enterprise%20fully%20managed%20devices%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1030218%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F226229%22%20target%3D%22_blank%22%3E%40Adrian%20Bishop%3C%2FA%3E%26nbsp%3B%20Support%20has%20told%20me%20that%20this%20issue%20will%20be%20fixed%20in%20the%20December%20update%20of%20Intune.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1032172%22%20slang%3D%22en-US%22%3ERe%3A%20Known%20Issue%20with%20SCEP%20profiles%20for%20Android%20Enterprise%20fully%20managed%20devices%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1032172%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F226229%22%20target%3D%22_blank%22%3E%40Adrian%20Bishop%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F10931%22%20target%3D%22_blank%22%3E%40Jeroen%20Dijkman%3C%2FA%3E%2C%20thanks%20for%20your%20comments!%3C%2FP%3E%0A%3CP%3EWe've%20checked%20with%20the%20team%2C%20and%20the%20fix%20has%20been%20rolled%20out.%20If%20the%20issue%20still%20persists%2C%20please%20message%20us%20with%20additional%20details%20for%20us%20to%20review!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1025157%22%20slang%3D%22en-US%22%3EKnown%20Issue%20with%20SCEP%20profiles%20for%20Android%20Enterprise%20fully%20managed%20devices%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1025157%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSTRONG%3EUpdate%3A%20This%20fix%20for%20this%20issue%20has%20now%20been%20rolled%20out.%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%E2%80%99ve%20seen%20an%20issue%20in%20the%20%E2%80%9CCommon%20name%E2%80%9D%20value%20of%20SCEP%20certificate%20profiles%20for%20Android%20Enterprise%20fully%20managed%20devices%20in%20Intune.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThese%20profiles%20can%20potentially%20fail%20to%20deploy%20because%20of%20how%20the%20Common%20Name%20value%20is%20interpreted%20in%20the%20Intune%20backend.%20Even%20if%20your%20certificates%20are%20deploying%20to%20devices%2C%20they%20may%20be%20using%20a%20different%20value%20for%20Common%20Name%20than%20SCEP%20profiles%20you%E2%80%99ve%20deployed%20for%20other%20platforms.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20style%3D%22display%3A%20inline%20!important%3B%20float%3A%20none%3B%20background-color%3A%20%23ffffff%3B%20color%3A%20%23333333%3B%20cursor%3A%20text%3B%20font-family%3A%20inherit%3B%20font-size%3A%2016px%3B%20font-style%3A%20normal%3B%20font-variant%3A%20normal%3B%20font-weight%3A%20300%3B%20letter-spacing%3A%20normal%3B%20line-height%3A%201.7142%3B%20orphans%3A%202%3B%20text-align%3A%20left%3B%20text-decoration%3A%20none%3B%20text-indent%3A%200px%3B%20text-transform%3A%20none%3B%20-webkit-text-stroke-width%3A%200px%3B%20white-space%3A%20normal%3B%20word-spacing%3A%200px%3B%22%3EWe%E2%80%99ll%20update%20this%20post%20when%20the%20fix%20for%20this%20issue%20is%20rolled%20out%20so%20you%20can%20make%20changes%20to%20impacted%20profiles.%20After%20that%20fix%20is%20in%2C%20you%20will%20have%20to%20take%20action%20to%20ensure%20that%20your%20SCEP%20profiles%20work%20as%20expected.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20existing%20SCEP%20profiles%2C%20we%20recommend%20that%20you%20delete%20the%20existing%20profile%20and%20create%20a%20new%20one%20with%20the%20same%20configuration%20after%20the%20fix%20has%20been%20rolled%20out.%26nbsp%3B%20This%20will%20ensure%20that%20the%20certificates%20you%20issued%20are%20issuing%20certificate%20subject%20names%20consistent%20with%20our%20SCEP%20profiles%20you%20may%20have%20for%20other%20platforms.%26nbsp%3B%20Once%20you%20create%20and%20deploy%20the%20updated%20SCEP%20profile%2C%20all%20devices%20targeted%20by%20the%20policy%20will%20receive%20a%20new%20certificate%20with%20the%20correct%20Common%20Name%20and%20the%20old%20certificate%20will%20be%20removed.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20do%20not%20take%20action%20to%20delete%20an%20impacted%20profile%2C%20the%20profile%20will%20get%20the%20correct%20Common%20Name%20value%20when%20the%20SCEP%20certificate%20is%20next%20renewed.%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EMore%20information%20about%20SCEP%20certificate%20profiles%20is%20available%20in%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fprotect%2Fcertificates-profile-scep%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3ECreate%20and%20assign%20SCEP%20certificate%20profiles%20in%20Intune%3C%2FA%3E%20doc.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E11%2F25%2F19%3A%20Updated%20with%20status%20of%20fix%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1025157%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20style%3D%22display%3A%20inline%20!important%3B%20float%3A%20none%3B%20background-color%3A%20%23ffffff%3B%20color%3A%20%23333333%3B%20cursor%3A%20text%3B%20font-family%3A%20inherit%3B%20font-size%3A%2016px%3B%20font-style%3A%20normal%3B%20font-variant%3A%20normal%3B%20font-weight%3A%20300%3B%20letter-spacing%3A%20normal%3B%20line-height%3A%201.7142%3B%20orphans%3A%202%3B%20text-align%3A%20left%3B%20text-decoration%3A%20none%3B%20text-indent%3A%200px%3B%20text-transform%3A%20none%3B%20-webkit-text-stroke-width%3A%200px%3B%20white-space%3A%20normal%3B%20word-spacing%3A%200px%3B%22%3EWe%E2%80%99ve%20seen%20an%20issue%20in%20the%20%E2%80%9CCommon%20name%E2%80%9D%20value%20of%20SCEP%20certificate%20profiles%20for%20fully%20managed%20devices%20in%20Intune.%26nbsp%3BThese%20profiles%20can%20potentially%20fail%20to%20deploy%20because%20of%20how%20the%20Common%20Name%20value%20is%20interpreted%20in%20the%20Intune%20backend.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1025157%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eknown%20issue%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1036494%22%20slang%3D%22en-US%22%3ERe%3A%20Known%20Issue%20with%20SCEP%20profiles%20for%20Android%20Enterprise%20fully%20managed%20devices%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1036494%22%20slang%3D%22en-US%22%3E%3CP%3EIve%20deleted%20my%20existing%20SCEP%20profile%20and%20created%20a%20new%20one.%26nbsp%3B%20However%2C%20the%20new%20profile%20has%20a%20status%20of%20FAILED%20to%20devcies.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20anyone%20else%20experiencing%20this%20issue%3F%26nbsp%3B%20The%20original%20SCEP%20profile%20was%20deploying%20user%20certficates%20to%20devices%20without%20issue.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1039413%22%20slang%3D%22en-US%22%3ERe%3A%20Known%20Issue%20with%20SCEP%20profiles%20for%20Android%20Enterprise%20fully%20managed%20devices%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1039413%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F226779%22%20target%3D%22_blank%22%3E%40Intune%20Support%20Team%3C%2FA%3E%26nbsp%3B%20I%20tested%20the%20fix%20and%20can%20confirm%20that%20for%20us%20it%20is%20working%20now.%20The%20certificate%20request%20is%20using%20the%20correct%20attribute%20for%20the%20common%20name.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1039588%22%20slang%3D%22en-US%22%3ERe%3A%20Known%20Issue%20with%20SCEP%20profiles%20for%20Android%20Enterprise%20fully%20managed%20devices%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1039588%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F344102%22%20target%3D%22_blank%22%3E%40a_naqui%3C%2FA%3E%26nbsp%3B%20I%20tested%20on%202%20different%20devices.%20I%20noticed%20on%20one%20device%20it%20took%20about%2015%20to%2020%20minutes%20for%20the%20certificate%20request%20to%20be%20processed.%20In%20the%20meantime%20the%20Intune%20console%20can%20give%20an%20error%20message%20on%20the%20device%20configuration%20page%20of%20the%20device.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1039621%22%20slang%3D%22en-US%22%3ERe%3A%20Known%20Issue%20with%20SCEP%20profiles%20for%20Android%20Enterprise%20fully%20managed%20devices%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1039621%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F10931%22%20target%3D%22_blank%22%3E%40Jeroen%20Dijkman%3C%2FA%3E%26nbsp%3B%20-%20I%20managed%20to%20get%20it%20working.%26nbsp%3B%20The%20issue%20was%20due%20to%20the%20NDES%20SSL%20cert%20having%20to%20be%20reapplied.%26nbsp%3B%20We%20upgraded%20our%20CA%20to%20server%202019%20and%20this%20stopped%20working.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECerts%20are%20now%20successfully%20deploying%20once%20again.%3C%2FP%3E%3C%2FLINGO-BODY%3E

Update: This fix for this issue has now been rolled out. 

 

We’ve seen an issue in the “Common name” value of SCEP certificate profiles for Android Enterprise fully managed devices in Intune.

 

These profiles can potentially fail to deploy because of how the Common Name value is interpreted in the Intune backend. Even if your certificates are deploying to devices, they may be using a different value for Common Name than SCEP profiles you’ve deployed for other platforms. 

 

We’ll update this post when the fix for this issue is rolled out so you can make changes to impacted profiles. After that fix is in, you will have to take action to ensure that your SCEP profiles work as expected.

 

For existing SCEP profiles, we recommend that you delete the existing profile and create a new one with the same configuration after the fix has been rolled out.  This will ensure that the certificates you issued are issuing certificate subject names consistent with our SCEP profiles you may have for other platforms.  Once you create and deploy the updated SCEP profile, all devices targeted by the policy will receive a new certificate with the correct Common Name and the old certificate will be removed.

 

If you do not take action to delete an impacted profile, the profile will get the correct Common Name value when the SCEP certificate is next renewed.

 

More information about SCEP certificate profiles is available in the Create and assign SCEP certificate profiles in Intune doc. 

 

11/25/19: Updated with status of fix

 

8 Comments
Senior Member

Good to see this issue is acknowledged. We actually have it and were working with MS support for months to figure it out. In the end because of 3 lines out of the Intune Device logs send to us by support we figured it out. Intune was actually taking the Display Name and using that as Common Name in the certificate request.

This can fail early in the process if the Display Name has special characters in it. Or it succeeds and provides the certificate with a Common Name value that is wrong. (In our case the Display Name) Then when using the certificate for connecting to for example Wifi it will fail the authentication.

 

Workaround for us was to use the exact same value for the Display Name and Common Name. But this is only feasible for some testing.

 

@Intune Support Team What would have been helpful in finding this issue must quicker is to have access to the Intune Device logs. As a customer I noticed straight away that the common name value used in the certificate request was wrong. But this error message only showed up in the Device logs.

Senior Member
Is there any update or time frame on when the fix will be deployed
Senior Member

@Adrian Bishop  Support has told me that this issue will be fixed in the December update of Intune. 

Hi @Adrian Bishop@Jeroen Dijkman, thanks for your comments!

We've checked with the team, and the fix has been rolled out. If the issue still persists, please message us with additional details for us to review!

Senior Member

Ive deleted my existing SCEP profile and created a new one.  However, the new profile has a status of FAILED to devcies.

 

Is anyone else experiencing this issue?  The original SCEP profile was deploying user certficates to devices without issue.

Senior Member

@Intune Support Team  I tested the fix and can confirm that for us it is working now. The certificate request is using the correct attribute for the common name.

Senior Member

@a_naqui  I tested on 2 different devices. I noticed on one device it took about 15 to 20 minutes for the certificate request to be processed. In the meantime the Intune console can give an error message on the device configuration page of the device.

 

Senior Member

@Jeroen Dijkman  - I managed to get it working.  The issue was due to the NDES SSL cert having to be reapplied.  We upgraded our CA to server 2019 and this stopped working.

 

Certs are now successfully deploying once again.