How-To: Issue SCEP Certificates to macOS Devices with Intune

In this page we will guide you on how to create an Intune profile to issue X509 certificates either for devices or users using SCEP for MacOS.

Introduction - How to Issue SCEP Certificates to macOS Devices with Intune

This guide shows how to issue X509 certificates to macOS devices with Microsoft Intune and SCEP. You will create:

  1. A Trusted Certificate profile to establish trust with your CA chain.
  2. A SCEP Certificate profile to request and install certificates for users or devices.

By the end, your macOS devices will be able to enroll and receive certificates from your EZCA SCEP CA.

Prerequisites for Issuing SCEP Certificates to macOS Devices with Intune

Before you begin, confirm the following prerequisites:

  1. You have created an Intune SCEP CA.
  2. You have registered the Keytos Intune application in your Entra ID tenant.
  3. You are an Intune administrator with permissions to create configuration profiles in Intune.

How to Issue SCEP Certificates to macOS Devices with Intune - Step by Step Guide

In this section, you will first create a Trusted Certificate profile to deploy CA certificates, then create a SCEP Certificate profile for certificate enrollment.

How to Download Your CA Certificates from EZCA

To issue certificates to your macOS devices using Intune, you first need to download the CA certificate from your EZCA portal and upload it to Intune as a trusted certificate. Follow these steps to download your CA certificate from EZCA:

  1. Navigate to your EZCA portal instance, such as portal.ezca.io.
  2. From the left-hand menu, select Certificate Authorities.
  3. Find the CA you created for Intune and click on the View Details button.
  4. For your CA’s region(s), click on the Download Certificate button to download the CA certificate.
  5. Repeat the previous step for each CA in your PKI chain. If you have a Root CA and an Intermediate CA, make sure to download both certificates.

How to Create an Intune Trusted Certificate Profile for macOS Devices

Before issuing certificates, devices must trust your issuing chain.

Follow these steps for macOS devices:

  1. Go to https://aka.ms/intuneportal

  2. Select: Devices > macOS > Configuration profiles.

  3. Click Create profile.

  4. Select Templates as the profile type.

  5. Select the Trusted Certificate template.

    How to Create macOS Trusted Certificate in Intune
  6. Click Create.

  7. Enter the Name and Description for this Intune certificate profile.

    Create macOS Trusted Certificate in Intune
  8. Upload the CA certificate you downloaded from EZCA.

  9. Select your Assignments and complete the profile creation.

  10. Repeat these steps for each CA certificate in your chain (Root CA and Issuing CA as applicable).

  11. Done! Your managed macOS devices will now trust certificates issued by your EZCA CA chain.

How to Create an Intune SCEP Profile for macOS Certificates

You can issue either device certificates or user certificates, depending on your scenario:

  1. Use device certificates for machine identity and device-based authentication.
  2. Use user certificates for user identity use cases.
  3. If needed, deploy both profile types.

Use the tabs below for the profile type you want to configure.

How to Create an Intune SCEP Profile For Device Certificates

The following steps will guide you on how to create an Intune SCEP profile to issue device certificates to your macOS devices.

  1. In the Intune Portal, click on + Create profile again to start creating a new configuration profile. Enter the following fields:

    • Profile type: select Templates.

    • Template name: select SCEP Certificate.

      Intune Create macOS SCEP Certificate Profile - Select Template
  2. Click Create.

  3. Under the Basics tab, enter the Name and Description for this Intune SCEP profile and click Next to proceed.

    Intune SCEP Certificate Basics
  4. Under the Configuration settings tab, configure your basic certificate settings:

    • Deployment Channel: select Device Channel.

    • Certificate type: select Device.

    • Subject name format: Leave this as the default of CN={{AAD_Device_ID}}.

    • Subject alternative name > Attribute: select DNS.

    • Subject alternative name > Value: enter {{DeviceId}}.

      Intune SCEP Certificate Subject SAN Values
  5. If you have Microsoft Entra hybrid-joined devices and plan to use your SCEP certificates for Key Distribution Center (KDC) authentication, add another Subject alternative name URI attribute with the value {{OnpremisesSecurityIdentifier}}. This fulfills the strong mapping requirements for KB5014754.

    Intune SCEP Certificate Subject SAN On-Premises Identifier
  6. For Certificate Validity Period, keep the default value of 1 year.

  7. For Key Usage, select both Digital Signature and Key Encipherment.

    Intune SCEP Key Usage
  8. For Key Size, select 2048.

    Intune SCEP Key Size
  9. For Hash Algorithm, select SHA-2.

    Intune SCEP Hash Algorithm
  10. In the Root Certificate field, click + Root Certificate and select the issuing CA you created in the Create Trusted Certificate Profile section.

    Intune SCEP Root Certificate
  11. For Extended Key Usage select Client Authentication (1.3.6.1.5.5.7.3.2).

    Intune SCEP Extended Key Usage
  12. Leave Renewal threshold at the default value of 20% so your certificates automatically renew when they reach 20% of their validity period remaining.

    Intune SCEP Renewal Threshold
  13. Paste your Intune SCEP Server URL that you copied from the KEYTOS-PKI portal into the SCEP Server URLs field.

    Add SCEP Server URL to Intune macOS Device
  14. Click Next.

  15. Under the Assignments and Applicability Rules sections, configure the target devices or users for this profile and click Next.

  16. Review your profile settings and click Create.

How to Create an Intune SCEP Profile For User Certificates

The following steps will guide you on how to create an Intune SCEP profile to issue user certificates to your macOS devices.

  1. In the Intune Portal, click on + Create profile again to start creating a new configuration profile. Enter the following fields:

    • Profile type: select Templates.

    • Template name: select SCEP Certificate.

      Intune Create macOS SCEP Certificate Profile - Select Template
  2. Click Create.

  3. Under the Basics tab, enter the Name and Description for this Intune SCEP profile and click Next to proceed.

    Intune SCEP Certificate Basics
  4. Under the Configuration settings tab, configure your basic certificate settings:

    • Certificate type: select User.

    • Subject name format: Leave this as the default of CN={{UserName}},E={{EmailAddress}}.

    • Subject alternative name > Attribute: select UPN.

    • Subject alternative name > Value: enter {{UserPrincipalName}}.

      Intune SCEP Certificate Subject SAN Values
  5. If you have Microsoft Entra hybrid-joined devices and plan to use your SCEP certificates for Key Distribution Center (KDC) authentication, add another Subject alternative name URI attribute with the value {{OnpremisesSecurityIdentifier}}. This fulfills the strong mapping requirements for KB5014754.

    Intune SCEP Certificate Subject SAN On-Premises Identifier
  6. For Certificate Validity Period, keep the default value of 1 year.

  7. For Key Storage Provider (KSP), set this to Enroll to Trusted Platform Module (TPM) KSP, otherwise fail to ensure your private keys are securely stored in the TPM. If you need to support PCs without a TPM and are ok with the risk of software based keys, you can select another option, such as fallback to software KSP.

    Intune SCEP Key Storage Provider
  8. For Key Usage, select both Digital Signature and Key Encipherment.

    Intune SCEP Key Usage
  9. For Key Size, select 2048.

    Intune SCEP Key Size
  10. For Hash Algorithm, select SHA-2.

    Intune SCEP Hash Algorithm
  11. In the Root Certificate field, click + Root Certificate and select the issuing CA you created in the Create Trusted Certificate Profile section.

    Intune SCEP Root Certificate
  12. For Extended Key Usage select Client Authentication (1.3.6.1.5.5.7.3.2).

    Intune SCEP Extended Key Usage
  13. Leave Renewal threshold at the default value of 20% so your certificates automatically renew when they reach 20% of their validity period remaining.

    Intune SCEP Renewal Threshold
  14. Paste your Intune SCEP Server URL that you copied from the KEYTOS-PKI portal into the SCEP Server URLs field.

    Add SCEP Server URL to Intune macOS Device
  15. Click Next.

  16. Under the Assignments and Applicability Rules sections, configure the target devices or users for this profile and click Next.

  17. Review your profile settings and click Create.