Certificates
17 TopicsIntune certificate updates: Action may be required for continued connectivity
Read this article for certificate updates coming to Intune and many other services. Most management scenarios will work without action, however, look at the scenarios below and take action as needed!30KViews4likes8CommentsAndroid Enterprise SCEP user and device issuing errors
Hi, We are attempting to deliver Android Enterprise SCEP certificates (both user and device based) and both seem to fail. We have our environment set up for iOS SCEP and Android Device Admin SCEP certificates and they work fine. Using the same settings in the Android Enterprise profiles they fail with the error of "0 (No error code)" Does anyone know of anything that might be causing this? I reached out to the networking team to look in the logs, but they don't see any that sticks out that would cause this to fail.9.7KViews2likes7CommentsAndroid Enterprise Wifi deployment using SCEP Cert problems
Hi all, I am trying to setup android phones to connect to the wifi through a wifi profile. We use SCEP certificates. The trusted root certificate and the SCEP certificate deploy successfully to the device via Intune. The trusted root CA automatically gets put into the User store (dont know if this is causing the issue as its not in system store). However, we cant see the deployed SCEP certificate on the phone without using an app called 'My Certificates'. This confirms that both the CA and SCEP certificate are on the device. The Wifi profile is then sent to the device and again this says successful on intune but the phone doesnt connect to the wifi. The SSID it is trying to connect to appears but it doesn't connect. Looks like it tries connecting and then fails. Nothing can be seen on the networks ISE servers so it doesnt even look like its getting that far. Then tried to add the wifi manually. WPA2 enterprise. When I select the option to select a certificate, it shows the ssid name (mustve got this from the wifi profile deployment) with '_NULL' at the end? Dont understand what this is or what it means? Tried selecting the null certificate but this doesnt connect either. Connection we want to use is EAP-TLS. We DONT use the Company portal. The android phones are fully managed corporate devices. The above method to deploy the Certs and wifi profile works fine with iOS devices but not android Any help would be greatly appreciated Thanks SA2.8KViews0likes1CommentTrusted certificate profile in Intune Stuck at Pending
We need to deploy our Root CA and subordinate issuing CA Certificates to our Intune managed AAD only devices to support SCEP. We created atrusted certificate profilein Intune to provision these certs but however comma this profile is stuck at pending... How do I troubleshootwhat is going on? Microsoft how have I failed you 😞 Intune supports use of the Simple Certificate Enrollment Protocol (SCEP) toauthenticate connections to your apps and corporate resources. SCEP uses the Certification Authority (CA) certificate to secure the message exchange for the Certificate Signing Request (CSR). When your infrastructure supports SCEP, you can use IntuneSCEP certificateprofiles (a type of device profile in Intune) to deploy the certificates to your devices. Configure infrastructure to support SCEP certificate profiles with Microsoft Intune | Microsoft Learn To use a SCEP certificate profile, devices must trust your Trusted Root Certification Authority (CA). Use atrusted certificate profilein Intune to provision the Trusted Root CA certificate to users and devices.2.2KViews0likes1CommentAnnouncement: How to Request a Certificate with a Custom Subject Alternative Name
First published on CLOUDBLOGS on Apr 21, 2010 [Today's post comes from Carol Bailey] I'm really pleased to be able to announce a recent publication from the Certificate Services documentation team that will help our customers running Configuration Manager in native mode: How to Request a Certificate With a Custom Subject Alternative Name.5.5KViews0likes0CommentsKnown Issue: Logging Information for Native Mode Certificate Selection
First published on CLOUDBLOGS on Dec 15, 2009 [Carol Bailey has contributed today's post]A couple of issues recently came to our attention from the TechNet forums with regard to native mode certificate selection when there is more than one available certificate that could be used:When a certificate in the certificate store has expired, we log this and Trace32 highlights it as an error, which might be interpreted that it is this certificate that is selected.357Views0likes0CommentsUpdated Blog Post for How to Publish the CRL on a Separate Web Server – for Delta CRLs
First published on CLOUDBLOGS on Aug 13, 2009 [Carol Baileyhas updated her previous post "How to Publish the CRL on a Separate Web Server"] We've recently updated our blog post for publishing the CRL on a separate Web server because the instructions were missing the variable in the paths, which is needed for delta CRLs.424Views0likes0Comments