Configuring SCEP Profiles in Intune: A High-Level Overview

Digital certificates provide stronger cryptographic protection than usernames and passwords, but issuing them at scale can be challenging, especially when managing many devices. For organizations using Microsoft Intune, SCEP (Simple Certificate Enrollment Protocol) simplifies certificate enrollment by allowing managed devices to obtain digital certificates from a certificate authority (CA) without requiring end-user interaction. This article […]

Secure Your Devices: Configuring SCEP Profiles in Intune Explained
Key Takeaways
  • SCEP streamlines the certificate issuance process using an API to facilitate secure communication between clients (your managed devices) and your Public Key Infrastructure.
  • SCEP has some vulnerabilities. Using the Intune Third Party CA method is safer because it verifies devices in Intune before distributing SCEP certificates.
  • Intune SCEP Profiles can be used to issue user certificates or device/machine certificates, depending on the configuration settings.

Digital certificates provide stronger cryptographic protection than usernames and passwords, but issuing them at scale can be challenging, especially when managing many devices.

For organizations using Microsoft Intune, SCEP (Simple Certificate Enrollment Protocol) simplifies certificate enrollment by allowing managed devices to obtain digital certificates from a certificate authority (CA) without requiring end-user interaction.

This article covers the prerequisites, certificate attributes, and steps for configuring a SCEP profile in Intune.

Watch the video below to learn more about SCEP enrollment:

Prerequisites for Configuring an Intune SCEP Profile

Before you start, you must have:

To begin, you must create a trusted certificate profile for the devices you intend to use for the SCEP configuration. This trusted certificate profile helps as you deploy the root CA or intermediate CA on the device. It also helps establish trust between the device and the issuing CA.

To create a trusted certificate profile, you need to configure your PKI with Intune. For that, you can use either of the following methods:

  • Intune third-party CA partner
  • Intune SCEP API token

We recommend using the Intune CA partner integration method because it checks the device’s authorization in Intune before distributing SCEP certificates, while the API token method does not.

Additionally, the API token SCEP integration is relatively vulnerable because it uses a shared secret and a SCEP URL. The shared secret is essentially a pre-shared key that is visible within the URL, which makes this method riskier than necessary.

See your security gap before attackers do.

See continuous trust in action on a platform that includes RADIUS, PKI and AI security.

Customize Your Video Demo

Attributes in SCEP Certificates

SCEP profiles in Intune include several attributes that control how certificates are generated, stored, and used. Understanding these settings can help you choose the appropriate values when configuring your SCEP profile.

Key SCEP certificate attributes include:

  • Certificate type: Determines whether the certificate is issued to a user or a device and where Intune stores it.
  • Subject name format: Defines the subject name that Intune includes in the certificate request. Available variables differ depending on whether you select a user or device certificate.
  • Subject alternative name (SAN): Adds additional identifying information to the certificate, such as a user principal name, email address, or device ID.
  • Certificate validity period: Determines how long the issued certificate remains valid before it expires.
  • Key storage provider (KSP): Determines where the certificate’s private key is stored. On Windows, select Enroll to Trusted Platform Module (TPM) KSP if present, otherwise Software KSP to use the TPM when available and fall back to the Software KSP when it isn’t.
  • Key usage: Defines how the certificate’s key can be used. For certificates used for authentication, select Digital signature and Key encipherment when both are supported by the intended authentication configuration.
  • Key size (bits): Determines the size of the RSA key. 2048 bits is a commonly supported choice; larger keys can provide additional cryptographic strength but may have platform or KSP limitations.
  • Hash algorithm: Determines the hashing algorithm used with the certificate’s signature. SHA-2 is the appropriate choice for modern supported devices.
  • Root certificate: Identifies the trusted CA certificate profile associated with the issuing CA. The device must trust the CA chain used to issue the SCEP certificate.
  • Extended key usage (EKU): Specifies the purposes for which the certificate can be used. Client Authentication is commonly required for certificate-based authentication.
  • Object identifier (OID): Identifies a specific certificate purpose or policy. Different OIDs can help authentication systems distinguish certificates issued for different purposes.

How to Configure a SCEP Profile in Intune

A SCEP profile in Intune defines the certificate settings that managed devices use to request certificates from a CA. These settings determine how user or device certificates are configured, including the certificate subject, SAN, and other enrollment parameters. Once issued, the certificate can be used for certificate-based authentication, such as connecting to an enterprise Wi-Fi network.

Step 1: Create a SCEP Certificate Profile

Start by creating a SCEP certificate profile in the Microsoft Intune admin center and selecting the device platform where the certificate will be deployed:

  1. Sign in to the Microsoft Intune admin center (formerly Microsoft Endpoint Manager).
  2. Select Devices > Configuration profiles > Create profile.
  3. From the Platform drop-down list, select the device platform for this SCEP certificate. You can choose one of the following platforms for device restriction settings:
    1. Android
    2. iOS
    3. macOS
    4. Windows 10 and later
  4. From the Profile Type drop-down list, select Templates and then choose SCEP certificate. Click Create.

Create a SCEP certificate using a template.

Note: You must create a separate profile for each Operating System platform. The steps to create trusted certificates are similar for each device platform.

Step 2: Configure the SCEP Certificate Profile Settings

After creating the profile, configure the certificate settings that determine how Intune generates the certificate request and how the issued certificate can be used.

On the SCEP certificate screen, enter a name and description for the profile, then select Next.

SCEP certificate basic configuration includes a name and a description.

Certificate Type

On the next screen, under Certificate Type, select whether the certificate will identify a user or device:

  • User: Select this option when the certificate should identify an individual user.
  • Device: Select this option when the certificate should identify the device, such as a kiosk or a Windows device using the Local Computer certificate store.

Screenshot showing SCEP certificate attribute configuration settings in Intune.

Subject Name Format

Next, choose how Intune creates the subject name in the certificate request.

For user certificates, you can select one of the following options:

  • CN={{UserName}}

  • CN={{EmailAddress}}

  • CN={{UserPrincipalName}}

For device certificates, you can select one of the following options:

  • CN={{DeviceName}}

  • CN={{AAD_Device_ID}}

Steps to create a device SCEP certificate in Intune.

Subject Alternative Name

Next, choose how Intune creates the certificate’s SAN. Use an attribute that uniquely identifies the user or device.

For user certificates, choose one of the following:

  • Email address: {{UserName}}
  • Email address: {{UserPrincipalName}}
  • Email address: {{AAD_Device_ID}}

For device certificates, choose one of the following:

  • Email address: {{DeviceName}}
  • Email address: {{AAD_Device_ID}}

SCEP subject alternative name selection.

Note: To test whether attributes are configured correctly, check the General Events section in the JoinNow Management Portal for event messages such as Device Creation Failed, which indicates the attributes are not mapped correctly.

Key Storage Provider

For Windows devices, choose where to store the certificate’s private key. Select Enroll to Trusted Platform Module (TPM) KSP if present, otherwise Software KSP.

This uses the TPM when one is available and falls back to the Windows Software KSP when it isn’t.

Key storage provider selection options include Enroll in Trusted Platform Module (TPM) KSP or Software KSP.

Key Usage

Select the key usage options required by the certificate. For most SCEP certificate profiles used for authentication, select both:

  • Digital signature: Allows the certificate to be used for digital signatures
  • Key encipherment: Allows the certificate to be used for key exchange when the key is encrypted

For configuring Key Usage in SCEP select both Key Encipherment and Digital Signature for best certificate security.

Key Size (Bits)

Select the key size required by your certificate configuration:

  • 2048 bits is a commonly supported choice.
  • Intune also supports 4096-bit keys on current versions of Android, iOS/iPadOS, macOS, and Windows, although Windows devices can store 4096-bit keys only in the Software KSP.

When choosing key size, select the maximum size available.

Hash Algorithm

Select the strongest hash algorithm supported by the devices that will use the certificate. Intune supports SHA-1 and SHA-2 options depending on the platform, but SHA-2 is generally the appropriate choice for current devices.

Select the highest level of security when choosing the hash algorithm for SCEP certificates.

Note: Certificate type is not a setting on Android SCEP Profiles. You must create a separate profile for each OS platform. The steps to create trusted certificates are similar for each device platform.

Root Certificate

Click the + sign and select the trusted certificate profile you configured for the CA that will issue the SCEP certificate. The device must trust the CA before it can use the SCEP-issued certificate.

Select the appropriate intermediate and root certificates of the issuing CA.

Extended Key Usage

Add the EKU values that define the certificate’s intended purpose. For certificate-based authentication, select Client Authentication so the user or device can authenticate to a server.

 Select the appropriate extended key usage for your certificate.

Enrollment Settings

Next, configure the certificate renewal and SCEP server settings:

  • Renewal threshold (%): Enter the percentage of the certificate’s lifetime that should remain when the device begins requesting renewal. For example, a value of 20% means renewal begins when 80% of the certificate’s lifetime has elapsed.
  • SCEP Server URLs: Enter the SCEP server URL provided by your SecureW2 SCEP integration.

Screenshot showing the final steps to create a SCEP certificate profile.

Then, select Next and assign the profile to the appropriate groups. For Windows profiles, configure any required Applicability Rules, then review the settings and select Create.

A screenshot showing how to select Applicability Rules when configuring a SCEP certificate.

A screenshot showing the final step of SCEP configuration.

The security plan that scales with you.

Our solutions can scale from mid-market to global enterprises. Compare options and see how our solutions protect you from costly breaches and ensure peace of mind.

Check Our Prices

Deploy Users and Devices with Intune’s Built-in Wi-Fi Settings

After configuring SCEP integration for Intune, you can use Intune’s built-in Wi-Fi settings to deploy to users and devices. For that, you must configure the appropriate Wi-Fi settings so the certificate can connect to the desired server automatically.

You can use the SCEP-enrolled certificate to configure the desired devices for EAP-TLS authentication by adding the SCEP URL to the Intune devices so that the SCEP gateway can deploy the necessary configurations.

If you’re having trouble with your SCEP configuration, our SCEP Profile Troubleshooting Guide explains the most common errors and how to fix them.

SCEP relies on a certificate authority to issue certificates to Intune-managed devices. As certificate deployments scale, organizations also need to manage certificate issuance and lifecycle management alongside their Intune environment.

Automate SCEP Certificate Management in Intune

Managing SCEP certificates at scale requires more than an Intune profile. Organizations also need a PKI that can issue, renew, revoke, and manage certificates throughout their lifecycle without relying on manual processes or on-premises CA infrastructure.

SecureW2JoinNow Dynamic PKI provides a cloud-managed PKI that integrates with Intune and other major mobile device management (MDM) platforms. It automates certificate enrollment through SCEP and gives administrators a central place to manage certificate policies, issuance, renewal, and revocation.

Dynamic PKI also supports certificate deployment across different device ecosystems through API gateways, so organizations aren’t tied to a single MDM platform. Administrators can configure certificate policies to match their authentication requirements and troubleshoot SCEP enrollment issues through the SecureW2 Management Portal.

For organizations using Intune, this means the certificate infrastructure can run alongside the existing MDM environment without requiring an on-prem CA. To see how SecureW2 can simplify SCEP enrollment and certificate management, request a free demo.


Frequently Asked Questions

What is an Intune SCEP profile?

An Intune SCEP profile is a configuration profile used to automatically request and deploy certificates to managed devices through the Simple Certificate Enrollment Protocol (SCEP). Organizations commonly use Intune SCEP profiles to support certificate-based authentication for Wi-Fi, VPNs, applications, and wired networks without requiring users to manually install certificates.

How does SCEP work with Intune?

Intune uses SCEP to automate certificate enrollment for managed devices. After an administrator creates and assigns a SCEP profile, Intune delivers the configuration to the device. The device then sends a certificate request to a SCEP server or certificate authority (CA), which validates the request and issues a certificate. The certificate is installed automatically and can then be used for secure authentication methods such as EAP-TLS.

What is SCEP used for?

SCEP is used to simplify and automate certificate enrollment and management for devices. Organizations commonly use SCEP to deploy certificates for:

  • WPA2/WPA3-Enterprise Wi-Fi authentication
  • VPN authentication
  • Wired 802.1X authentication
  • Device identity and compliance
  • Secure access to enterprise applications

SCEP helps eliminate manual certificate installation while improving scalability and security.

What devices support Intune SCEP profiles?

Microsoft Intune supports SCEP certificate deployment across many platforms, including:

  • Windows
  • macOS
  • iOS and iPadOS
  • Android

Supported features and configuration options may vary depending on the operating system and device management method.

Is SCEP secure?

SCEP can provide strong security when properly configured alongside a trusted PKI and certificate authority. Modern deployments often combine SCEP with certificate-based authentication methods such as EAP-TLS to eliminate password-based authentication risks. Organizations can further improve security by using trusted device validation, strong cryptographic algorithms, and automated certificate lifecycle management.