How To Distribute Network Profiles to Windows Devices via Microsoft Intune

To connect an Intune-managed Windows device to your network, you need to distribute a network profile that includes the necessary network settings, authentication methods, and certificates via Microsoft Intune. Follow this guide to configure all the Intune policies and settings for Windows devices to connect to your network.

Overview - How to Distribute Network Profiles to Windows Devices via Intune

To connect an Intune-managed Windows device to your network, you need to distribute a network profile that includes the necessary network settings, authentication methods, and certificates. This guide will walk you through the steps to configure and push these profiles to Windows devices using Microsoft Intune.

What Intune Configuration Policies Do I Need to Create to Distribute Network Profiles to Windows Devices?

For a Windows device to successfully connect to your network using a network profile, you need to create and configure the following Intune configuration policies:

  1. Trusted Certificate Policy: This policy ensures that the Windows device trusts your Shield’s Root CA certificate, which is necessary for establishing a secure connection to your network.
  2. SCEP Certificate Policy: This policy provisions each Windows device with a unique identity certificate via the Simple Certificate Enrollment Protocol (SCEP), enabling secure authentication with your network.
  3. Wi-Fi Profile Policy: This policy contains the network settings, such as SSID, security type, and authentication method, required for the Windows device to connect to your network automatically using the certificates provisioned through Intune.

Step-by-Step Guide - How To Configure Network Profile Intune Configuration Policies for Windows

Follow these steps to configure and push the necessary Intune configuration policies for Windows devices:

Prerequisites for Configuring Windows Network Profiles via Intune

Before you begin configuring network profiles for Windows devices via Intune, ensure that you have completed all the necessary prerequisites:

  1. The Keytos Entra ID applications are registered in your tenant.
  2. You have signed up for a Keytos Shield Plan.
  3. You have existing access policies in Keytos Shield.
  4. You are a Subscription Owner or Network Administrator.
  5. You have checked Intune under “Which MDMs do you use to manage your devices” in Keytos Shield.
  6. You are an Intune Administrator.

Step 1 - How to Push Your Shield CA Certificates as Trusted Certificates on Windows Devices via Intune

For your devices to establish a secure connection to Keytos Shield, you need to distribute the Shield CA certificates (both Root and Issuing) to your devices via Intune.

How to Download Your Shield Root and Issuing CA Certificates

Begin by downloading your Shield Root and Issuing CA certificates from the Keytos Shield portal.

  1. Log in to your Keytos Shield portal.

  2. From the left-hand navigation bar, click on Network Profiles.

  3. At the top of the page, select the Settings tab.

    Keytos Shield Settings tab highlighted
  4. Scroll down to the Certificate Authority and Enrollment section and expand the Intune subsection.

    Not seeing the Intune subsection? Make sure to enable Intune under the Mobile Device Management section further up on the page and save your changes.

  5. Next to rootca.cer, click Download save it to your local machine.

  6. Next to issuingca.cer, click Download and save it to your local machine as well.

    Keytos Shield Download Root CA and Issuing CA Certificate File button highlighted

How to Push Your CA Certificates to Your Windows Devices via Intune

Now that you have your Shield CA certificates downloaded, the next step is to push them to your devices’ Trusted Store using Microsoft Intune.

  1. Navigate to the Intune portal: https://aka.ms/Intune

  2. From the left-hand menu, click on Devices.

    Intune Devices
  3. From the left-hand sub-menu, click Windows to manage Windows devices.

    Intune Windows Sub-Menu
  4. From the left-hand sub-menu, click on Configuration Profiles.

    Intune Configuration Profiles
  5. Click on the + Create button at the top of the list, then + New Policy.

    Intune Create Configuration Profile
  6. Under Create a profile, select the following options and click Create:

    • Platform: Windows 10 and later

    • Profile type: Templates

    • Template name: Trusted certificate

      Intune Create Trusted Certificate Profile
  7. Within the Basics tab, fill out the fields:

    • Name: Friendly name for your organization

    • Description: Description for your organization

      Intune Trusted Certificate Profile Name
  8. Click on Next.

  9. Within the Configuration settings tab, configure the following options:

    • Certificate file: Select the CA certificate you downloaded earlier from Keytos Shield (rootCA.cer).

    • Destination store: Select the appropriate store based on the type of CA certificate:

      • Computer certificate store - Root (if a root CA certificate)
      • Computer certificate store - Intermediate (if an intermediate CA certificate).
      Intune Trusted Certificate Profile Settings
  10. Click on Next.

  11. Within the Assignments tab, select the users, groups or devices you want to deploy this profile to.

  12. Click on Next.

  13. Within the Applicability Rules tab, add any rules if needed, then click on Next.

  14. Click on Create to finish creating the profile.

  15. Repeat the above steps to distribute all necessary CA certificates (both root and intermediate) to your Windows devices.

How to Verify the Keytos Shield CA Certificates Have Been Pushed by Intune

To verify that the Shield CA certificates have been successfully pushed to your Windows devices via Intune, follow these steps:

  1. On a Windows device, open the Run dialog by pressing Win + R.
  2. Type certlm.msc and press Enter to open the Local Computer Certificate Manager.
  3. Navigate to Trusted Root Certification Authorities > Certificates and check for the presence of the Shield Root CA certificate.
  4. Navigate to Intermediate Certification Authorities > Certificates and check for the presence of the Shield Issuing CA certificate.

If both certificates are present in their respective stores, the deployment via Intune was successful.

Not seeing the Shield CA certificates in the respective stores? Ensure that the Intune profile has been correctly assigned to the device and that the device has synced with Intune. You can manually trigger a sync by going to Settings > Accounts > Access work or school, selecting your work or school account, and clicking Sync.

Step 2 - How to Issue a SCEP Certificate to a Windows Device via Intune

A SCEP (Simple Certificate Enrollment Protocol) certificate allows your Windows device to authenticate with its own unique certificate, which can be used for secure network access and other authentication purposes. Follow these steps to issue a SCEP certificate to your Windows device via Intune.

How to Get Your Keytos Shield SCEP Server URL

To issue SCEP certificates to your Windows devices via Intune, you will need the SCEP Server URL from your Keytos Shield portal.

  1. Open the Keytos Shield portal.

  2. From the left-hand menu, navigate to Network profiles.

  3. In the top tab bar, select Settings.

    Keytos Shield Network Profile Settings
  4. Under Mobile Device Management, make sure Intune is enabled.

    Enable Intune SCEP in Keytos Shield
  5. Under Certificate Authority and Enrollment, copy the Intune SCEP URL for your issuing CA. You’ll need this in a little bit.

    Get the Intune CA SCEP URL from Keytos Shield

How to Create a SCEP Profile for Windows Devices in Intune

The next step is to create your SCEP profile for Windows devices in Intune.

How to Create an Intune SCEP Profile For Device Certificates

The following steps will guide you on how to create an Intune SCEP profile to issue device certificates to your Windows devices.

  1. In the Intune Portal, click on + Create profile again to start creating a new configuration profile. Enter the following fields:

    • Platform: select Windows 10 and later.

    • Profile type: select Templates.

    • Template name: select SCEP Certificate.

      Intune Create Windows SCEP Certificate Profile - Select Template
  2. Click Create.

  3. Under the Basics tab, enter the Name and Description for this Intune SCEP profile and click Next to proceed.

    Intune SCEP Certificate Basics
  4. Under the Configuration settings tab, configure your basic certificate settings:

    • Certificate type: select Device.

    • Subject name format: Leave this as the default of CN={{AAD_Device_ID}}.

    • Subject alternative name > Attribute: select URI.

    • Subject alternative name > Value: enter {{DeviceId}}.

      Intune SCEP Certificate Subject SAN Values
  5. If you have Microsoft Entra hybrid-joined devices and plan to use your SCEP certificates for Key Distribution Center (KDC) authentication, add another Subject alternative name URI attribute with the value {{OnpremisesSecurityIdentifier}}. This fulfills the strong mapping requirements for KB5014754.

    Intune SCEP Certificate Subject SAN On-Premises Identifier
  6. For Certificate Validity Period, keep the default value of 1 year.

  7. For Key Storage Provider (KSP), set this to Enroll to Trusted Platform Module (TPM) KSP, otherwise fail to ensure your private keys are securely stored in the TPM. If you need to support PCs without a TPM and are ok with the risk of software based keys, you can select another option, such as fallback to software KSP.

    Intune SCEP Key Storage Provider
  8. For Key Usage, select both Digital Signature and Key Encipherment.

    Intune SCEP Key Usage
  9. For Key Size, select 2048.

    Intune SCEP Key Size
  10. For Hash Algorithm, select SHA-2.

    Intune SCEP Hash Algorithm
  11. In the Root Certificate field, click + Root Certificate and select the issuing CA you created in the Create Trusted Certificate Profile section.

    Intune SCEP Root Certificate
  12. For Extended Key Usage select Client Authentication (1.3.6.1.5.5.7.3.2).

    Intune SCEP Extended Key Usage
  13. Leave Renewal threshold at the default value of 20% so your certificates automatically renew when they reach 20% of their validity period remaining.

    Intune SCEP Renewal Threshold
  14. Paste your Intune SCEP Server URL that you copied from the Keytos Shield portal into the SCEP Server URLs field.

    Add SCEP Server URL to Intune Windows Device
  15. Click Next.

  16. Under the Assignments and Applicability Rules sections, configure the target devices or users for this profile and click Next.

  17. Review your profile settings and click Create.

  18. Done! Your managed Windows devices will now start receiving device certificates issued from your Keytos Shield SCEP CA based on the assignment and applicability rules you set.

How to Create an Intune SCEP Profile For User Certificates

The following steps will guide you on how to create an Intune SCEP profile to issue user certificates to your Windows devices.

  1. In the Intune Portal, click on + Create profile again to start creating a new configuration profile. Enter the following fields:

    • Platform: select Windows 10 and later.

    • Profile type: select Templates.

    • Template name: select SCEP Certificate.

      Intune Create Windows SCEP Certificate Profile - Select Template
  2. Click Create.

  3. Under the Basics tab, enter the Name and Description for this Intune SCEP profile and click Next to proceed.

    Intune SCEP Certificate Basics
  4. Under the Configuration settings tab, configure your basic certificate settings:

    • Certificate type: select User.

    • Subject name format: Leave this as the default of CN={{UserName}},E={{EmailAddress}}.

    • Subject alternative name > Attribute: select UPN.

    • Subject alternative name > Value: enter {{UserPrincipalName}}.

      Intune SCEP Certificate Subject SAN Values
  5. If you have Microsoft Entra hybrid-joined devices and plan to use your SCEP certificates for Key Distribution Center (KDC) authentication, add another Subject alternative name URI attribute with the value {{OnpremisesSecurityIdentifier}}. This fulfills the strong mapping requirements for KB5014754.

    Intune SCEP Certificate Subject SAN On-Premises Identifier
  6. For Certificate Validity Period, keep the default value of 1 year.

  7. For Key Storage Provider (KSP), set this to Enroll to Trusted Platform Module (TPM) KSP, otherwise fail to ensure your private keys are securely stored in the TPM. If you need to support PCs without a TPM and are ok with the risk of software based keys, you can select another option, such as fallback to software KSP.

    Intune SCEP Key Storage Provider
  8. For Key Usage, select both Digital Signature and Key Encipherment.

    Intune SCEP Key Usage
  9. For Key Size, select 2048.

    Intune SCEP Key Size
  10. For Hash Algorithm, select SHA-2.

    Intune SCEP Hash Algorithm
  11. In the Root Certificate field, click + Root Certificate and select the issuing CA you created in the Create Trusted Certificate Profile section.

    Intune SCEP Root Certificate
  12. For Extended Key Usage select Client Authentication (1.3.6.1.5.5.7.3.2).

    Intune SCEP Extended Key Usage
  13. Leave Renewal threshold at the default value of 20% so your certificates automatically renew when they reach 20% of their validity period remaining.

    Intune SCEP Renewal Threshold
  14. Paste your Intune SCEP Server URL that you copied from the Keytos Shield portal into the SCEP Server URLs field.

    Add SCEP Server URL to Intune Windows Device
  15. Click Next.

  16. Under the Assignments and Applicability Rules sections, configure the target devices or users for this profile and click Next.

  17. Review your profile settings and click Create.

  18. Done! Your managed Windows devices will now start receiving user certificates issued from your Keytos Shield SCEP CA based on the assignment and applicability rules you set.

Step 3 - How to Create a Wi-Fi Profile in Intune for Certificate Authentication

Now that your device has the necessary CA certificates and SCEP certificate installed, you can proceed to create a Wi-Fi profile in Intune for certificate-based authentication.

How to Get Your RADIUS Server Names in Keytos Shield

To make sure your devices only trust the correct RADIUS servers, you will need to obtain the list of RADIUS server names from your Keytos Shield portal.

  1. From within Network profiles > Settings in the Keytos Shield portal, expand Certificate Authority and Enrollment.

    Keytos Shield Settings tab highlighted
  2. Expand your MDM’s section to view the available configuration options.

  3. You will see a list of RADIUS server names for your network profile. You will need these in the next section.

    Keytos Shield RADIUS server names list

How to Create a Windows Wi-Fi Profile in Intune

The final set of steps is to create a Windows Wi-Fi profile in Intune that tells your device how to connect to your secure network using the certificates issued in the previous steps.

  1. In the Intune Portal, click on + Create profile again to start creating a new configuration profile. Enter the following fields:

    • Platform: select Windows 10 and later.

    • Profile type: select Templates.

    • Template name: select Wi-Fi.

      Intune Wi-Fi Template
  2. Click on Create at the bottom of the page.

  3. Under the Basics tab, enter the Name and Description for this Intune Wi-Fi profile and click Next to proceed.

    Intune Wi-Fi Profile Name
  4. Enter the following required Configuration settings. Any field not mentioned below can be left as default or set to your organization’s preference:

    • Wi-Fi type: Enterprise

    • Wi-Fi name (SSID): Your Wi-Fi Network SSID (case sensitive)

    • Connection name: Friendly name for your users

    • Authentication mode: Select the mode based on whether your SCEP certificate is issued to the User or the Device.

    • Remember credentials: Set to No (not needed for certificate authentication).

    • Authentication period: 30 seconds is a recommended value we’ve seen work well for most environments.

    • Authentication retry delay: 1 second is a recommended value we’ve seen work well for most environments.

    • Maximum authentication failures: 10 is a recommended value we’ve seen work well for most environments.

    • Single sign-on (SSO): Disable

      Intune Wi-Fi Profile Basic Settings
  5. If your network controller supports Fast Roaming, fill out the Fast Roaming settings section with the following settings:

    • Enable pairwise master key (PMK) caching: Yes

    • Max PMK time stored in cache: We recommend setting this to the maximum (1440 minutes) to improve user experience.

    • Max number of PMKs in cache: We recommend setting this to the maximum (255) to improve user experience.

    • Enable pre-authentication: Yes

    • Max pre-authentication attempts: 10 is a recommended value we’ve seen work well for most environments.

      Intune Wi-Fi Profile Fast Roaming Settings
  6. Fill out the Server Trust section with the following settings:

    • EAP type: EAP-TLS

    • Certificate server names: Enter the CN and SAN values from your RADIUS server certificate that you noted earlier. Remove CN=, DNS Name=, and IP Address= prefixes when entering the values.

    • Root Certificates for server validation: Select both your Keytos Shield Root CA and Issuing CA trusted certificate profiles

      What is Server Trust in Intune Wi-Fi Policy
  7. Fill out the Client Authentication section with the following settings:

    • Authentication Method: SCEP Certificate

    • Client certificate for client authentication: Select the SCEP profile created earlier for issuing client certificates to your devices.

      Intune Wi-Fi Profile EAP-TLS SCEP
  8. Click on Next.

  9. Select the users, groups or devices you want to deploy this profile to and click Next.

    Intune Wi-Fi Profile Assignments
  10. Add any applicability rules if needed, then click on Next.

  11. Review your settings and click on Create.

    Intune Wi-Fi Profile Review
  12. Done! Your Wi-Fi profile is now created and will be pushed to your devices. Once the profile is applied, users will be able to connect to the Wi-Fi network using their SCEP-issued certificates.

  1. Go to your Intune portal: https://aka.ms/Intune

  2. Click on Devices

    Intune Devices
  3. Select the OS/platform you want to configure. In this case we will select Windows, but the setup is similar for other OS platforms.

  4. Click on Configuration Profiles.

    Intune Configuration Profiles
  5. Click on the + Create button at the top of the list.

    Intune Create Configuration Profile
  6. Select Windows 10 and later as the platform.

  7. Select Templates as the profile type.

  8. Select Wi-Fi as the template.

    Intune Wi-Fi Template
  9. Click on Create at the bottom of the page.

  10. Fill in the Name and Description fields with something meaningful for your organization.

  11. Click on Next.

    Intune Wi-Fi Profile Name
  12. Enter the following required Configuration settings. Any field not mentioned below can be left as default or set to your organization’s preference:

    • Wi-Fi type: Enterprise

    • Wi-Fi name (SSID): Your Wi-Fi Network SSID (Case Sensitive)

    • Connection name: Friendly name for your users

    • Authentication mode: User (Device is not supported for Entra ID Password authentication)

    • Remember credentials: Yes/No (Based on your preference)

    • Authentication period: 30 seconds is a recommended value we’ve seen work well for most environments.

    • Authentication retry delay: 1 seconds is a recommended value we’ve seen work well for most environments.

    • Maximum authentication failures: 10 is a recommended value we’ve seen work well for most environments.

    • Single sign-on (SSO): Disable

      Intune Wi-Fi Profile Basic Settings
  13. If your network controller supports Fast Roaming, fill out the Fast Roaming settings section with the following settings:

    • Enable pairwise master key (PMK) caching: Yes

    • Max PMK time stored in cache: We recommend setting this to the maximum (1440 minutes) to improve user experience.

    • Max number of PMKs in cache: We recommend setting this to the maximum (255) to improve user experience.

    • Enable pre-authentication: Yes

    • Max pre-authentication attempts: 10 is a recommended value we’ve seen work well for most environments.

      Intune Wi-Fi Profile Fast Roaming Settings
  14. Fill out the Server Trust section with the following settings:

    • EAP type: EAP-TTLS

    • Certificate server names: Enter the CN and SAN values from your RADIUS server certificate that you noted earlier. Remove CN=, DNS Name=, and IP Address= prefixes when entering the values.

    • Root Certificates for server validation: Select both your Keytos Shield Root CA and Intermediate CA certificate templates.

      What is Server Trust in Intune Wi-Fi Policy
  15. Fill out the Client Authentication section with the following settings:

    • Authentication Method: Username and Password

    • Non-EAP method (Inner method): Unencrypted Password (PAP) (Don’t worry the password is encrypted by the EAP-TTLS tunnel, it is not sent unencrypted over the air)

      Intune Wi-Fi Profile Client Authentication
  16. Click on Next.

  17. Select the users, groups or devices you want to deploy this profile to and click Next.

  18. Add any applicability rules if needed, then click on Next.

  19. Review your settings and click on Create.

    Intune Wi-Fi Profile Review
  20. Done! Your WiFi profile is now created and will be pushed to your devices. Once the profile is applied, users will be able to connect to the WiFi network using their Entra ID credentials.

How to Troubleshoot and Test an Intune Wi-Fi Profile in Windows

How to Test the Wi-Fi Certificate Authentication Setup

Now that you have created and deployed the WiFi profile, it’s important to test the setup to ensure everything is functioning correctly. Follow these steps to test your WiFi profile with Certificate Authentication:

  1. Begin on a device that is targeted by the Intune Wi-Fi profile you created.
  2. Force a sync with Intune to ensure the latest profiles are applied. You can do this by going to Settings > Accounts > Access work or school, selecting your work account, and clicking on Sync.
  3. Once the sync is complete, check that the WiFi profile has been applied by going to Settings > Network & Internet > Wi-Fi > Manage known networks. You should see the SSID you configured in the list.
  4. If you use User-based certificate authentication, attempt to connect to the Wi-Fi network. You should be connected without being prompted for a username or password. If you use Device-based certificates, the device should connect automatically without user interaction. You may need to restart the device to trigger the connection.