# Jamf Pro

Jamf Pro can request a new SCEP challenge for each device through a webhook, using its own **Dynamic** challenge type. No external CA registration or signing certificate is required — SimpleSCEP answers the webhook directly.

Webhook challenges last 15 minutes. Keep **One-time challenge** enabled on the endpoint.

## Requirements

An account with the **Webhooks** and **Configuration Profiles** privileges in Jamf Pro. The **SCEPChallenge** webhook event and the SCEP payload's **Dynamic** challenge type are both stock Jamf Pro features — no plug-in or extra licensing is needed on either side.

## Configure it

1. Under **Enrollment authentication**, select **Configure** for **Jamf Pro**. Set a webhook username, generate a password, and enable the method. The password is shown once.
2. In Jamf Pro, create a webhook for the **SCEPChallenge** event pointing at:

   ```text
   https://pki.example.com/integrations/jamf/scep-challenge/<endpoint-id>
   ```

3. Set the webhook's authentication to **HTTP Basic** with the username and password from step 1.
4. In the device's configuration profile, set the SCEP URL to the endpoint URL and select the dynamic challenge.

Deploy the endpoint's CA chain in the same configuration profile.

![The Jamf Pro dialog, with the webhook URL and the password shown once](/assets/docs/jamf-credential.png)

## SCEP certificate payload

Jamf's SCEP payload takes the endpoint URL and, for **Challenge Type**, **Dynamic** — not a static password. Key size, key usage, and subject follow the same rules as any other Apple MDM — see [SCEP for MDM platforms](/protocols/scep/mdm).

Certificate validity, the renewal window, and the extended key usages come from the endpoint's issuance policy, not the payload — see [SCEP](/protocols/scep).

## Rotate the credential

Select **Update**, then **Generate password** to rotate the credential. Rotation immediately invalidates the old password, so update the Jamf webhook at the same time.

Only a verifier is stored. Rotate a lost password.

## Revocation

Jamf Pro does not report revocations back to SimpleSCEP. Revoke certificates issued through Jamf from the Certificates page — this is immediate and updates the CRL and OCSP right away. Compare with [Microsoft Intune](/protocols/scep/intune), which syncs revocations hourly.

## Turn it off

Disable the **Jamf Pro** method under **Enrollment authentication** to stop issuing webhook challenges, or delete the endpoint entirely.

Turning it off stops Jamf-authenticated enrollment. It does not revoke certificates already issued.

## When the webhook stops working

In rough order of likelihood:

1. The password was rotated in SimpleSCEP but not updated on the Jamf webhook.
2. The webhook was deleted, disabled, or misconfigured in Jamf Pro.
3. The **Jamf Pro** method was disabled under **Enrollment authentication**.

Check **Recent enrollments** on the endpoint for the refusal reason before assuming the webhook itself is broken.

## Notes

- Webhook challenges cannot be pinned because Jamf requests them before the device CSR. Generate challenges directly when pinning is required. See [SCEP challenges and secrets](/protocols/scep/authentication).
- Deleting the endpoint deletes the webhook password with it.
- The webhook is device-facing traffic and is rate limited per endpoint and source address.
