Back
What are the Best SCEP Certificate Authorities (CAs) for SimpleMDM Environments?

What are the Best SCEP Certificate Authorities (CAs) for SimpleMDM Environments?

What Do I Need to Be Able to Push Certificates to My SimpleMDM-Managed Devices?

To be able to push certificates to your SimpleMDM-managed devices, there are two main requirements:

  • A SimpleMDM subscription to manage your Apple devices and deploy profiles that include certificates.
  • A SCEP certificate authority (CA) that integrates with your SimpleMDM environment to issue the necessary certificates to your devices.

Beyond that, you will at least need managed devices and a defined use case for the certificate (such as Wi-Fi authentication, S/MIME, or network access control).

Now that we’ve covered basic prerequisites of a SCEP CA in a SimpleMDM environment, we need to understand what options are available for SimpleMDM and how to evaluate them.

What SCEP Certificate Authorities (CAs) are Available for SimpleMDM?

There are several SCEP CA solutions that can integrate with SimpleMDM environments. Some of the most popular options include: EZCA, SCEPman, and SecureW2. In this article, we will compare and evaluate each of them to see what is the best SCEP CA for SimpleMDM.

EZCA: The Favorite PKI for Cloud-Native Microsoft Customers

EZCA is a cloud-based PKI and SCEP CA built for organizations in the Microsoft ecosystem. One of EZCA’s greatest strengths is its flexibility as a CA. It supports protocols beyond SCEP for broader PKI needs such as SSL/TLS use cases and additional enrollment protocols like ACME and EST. For teams that are hybrid or planning on migrating, EZCA has strong support for hybrid-joined environments and ADCS chaining. However, one major caveat to EZCA is that it only supports Entra ID as an SSO provider, so teams with no Microsoft presence should consider other options.

Focusing specifically on SCEP, EZCA provides the ability to directly download an Apple configuration profile from the portal. This makes configuring and distributing a SCEP certificate as simple as creating a SCEP CA, downloading the configuration profile, and uploading it to SimpleMDM. Additionally, EZCA has dedicated documentation for integrating with SimpleMDM.

EZCA has two main ways of achieving automatic certificate renewals: programmatic renewal and via your MDM. EZCA supports REST API, NuGet, Terraform, and a client app that can be used to renew certificates automatically. However, for teams that are looking for something more set-and-forget, automatic renewals can also be set up on the EZCA portal to tie back with your SimpleMDM.

Unlike SecureW2 or SCEPman, EZCA charges a flat monthly fee per CA for unlimited certificates, so cost remains the same as an organization grows. Additionally, pricing is transparent, with plans starting at $200 a month.

In conclusion, EZCA offers the best first-party SimpleMDM documentation with flexible options for deployment and renewals. It supports features beyond SCEP at a low-cost flat rate. Making it the best option for customers using Entra ID. However, since it only supports SSO with Entra ID, if your organization requires a different option EZCA may not be best for you.

Learn More About EZCA for SimpleMDM

SCEPman: A Focused Option for SCEP-Centric Deployments

SCEPman is a popular choice for organizations that are in a pure cloud-based SCEP environment. Despite what the name would imply, SCEPman supports protocols beyond SCEP such as EST, Active Directory GPO, and OCSP. However, SCEPman lacks support for ACME, public certificates, and is tightly dependent on Azure. While this may work fine for your current organizational needs, if your organizational needs ever change, SCEPman is more narrow than alternate providers and may restrict you.

One of the biggest differences between SCEPman and EZCA is that SCEPman must be run entirely in your own tenant. Your certificates and Root CA are stored directly in your own Azure Key Vault. This is a double-edged sword. Unlike EZCA, SCEPman is not a SaaS solution, meaning you are responsible for managing cloud resources, uptime, updates, disaster recovery, etc. At the same time, this means all data and certificates remain under your complete control and sovereignty which may be required for compliance. However, for most teams this is unnecessary complexity.

In terms of integration with Apple devices, SCEPman does not include a .mobileconfig direct download for Apple devices. It is also currently missing specific documentation for SimpleMDM, unlike EZCA.

SCEPman charges per user. For small teams this is reasonable (especially since SCEPman offers a free tier designed for organizations with less than 25 employees), but the costs greatly increase the larger your team is. Combine this with the infrastructure and expertise costs of running SCEPman in your Azure tenant and the costs can quickly add up.

In conclusion, SCEPman lacks flexibility for both its use case and ability to scale. It is narrowly focused on SCEP certificates for Azure teams that are willing to run the required infrastructure. For teams under 25 users, it has a free tier but since it requires running your own infrastructure, it may still requires around $100 USD in infrastructure costs.

SecureW2: A Turnkey PKI for Non-Azure Environments

SecureW2 offers a cloud-native PKI that works independently of any single infrastructure provider. It is a cloud-native SaaS with support for many SSO providers such as Entra ID, Okta, and OneLogin. This can be especially useful for teams that are in non-Azure or mixed environments.

In contrast to EZCA and SCEPman, SecureW2 is not dependent on the Microsoft stack. SecureW2 is also well suited for fully cloud-based environments.

SecureW2 charges through a custom quote that is not transparent, unlike SCEPman and EZCA. This makes it difficult to compare the pricing with alternatives. Unlike EZCA, SecureW2 requires yearly or multi-year contracts. Meaning that you are stuck with the provider for multiple years.

In conclusion, SecureW2’s major benefits are that it supports many SSO providers, includes built-in cloud RADIUS, but it lacks transparent pricing. Additionally, due to its independence from any single cloud infrastructure provider, it’s best for teams in non-Azure or mixed environments.

What is the Best SCEP Certificate Authority for SimpleMDM?

For most organizations, especially if you are in the Microsoft ecosystem, EZCA is usually the best SCEP certificate authority for SimpleMDM.

The TL;DR is:

  • Choose EZCA for the most well-rounded SCEP certificate authority for SimpleMDM (especially for teams that are migrating, hybrid-joined, or are currently within the Microsoft ecosystem). It features a flat per-CA pricing, features beyond SCEP, and SimpleMDM documentation.
  • Choose SecureW2 if you are in a non-Azure or mixed environment and want a built-in RADIUS.
  • Choose SCEPman if you already have the Azure dependency and the expertise required to run infrastructure in your own tenant.

If you want to see how EZCA can support SimpleMDM certificate enrollment and broader private PKI use cases, talk to a PKI expert and map out the right approach for your environment.

How Can I Get Started with EZCA for SimpleMDM?

Whether you’re new to certificate management or looking to migrate from an existing CA, getting started with EZCA for your SimpleMDM environment takes only a few minutes to set up. Simply deploy your first cloud SCEP CA, download the .mobileconfig from your portal, and start issuing certificates to your Apple devices. More information can be found in our step-by-step guide for integrating EZCA with SimpleMDM.

Start Your Free Trial of EZCA

Also make sure to book a call with one of our PKI experts to see how EZCA can support your SimpleMDM deployment and broader certificate management needs.

Book a Call with a PKI Expert