Configure the MDM with the endpoint URL and its CA bundle. Use separate endpoints for populations with different validity, naming, or key-usage requirements.

Deploy the CA chain in the same device profile as the SCEP payload. A device that does not trust the issuer will enroll and then fail to use the certificate for anything.

Apple — Jamf Pro, Kandji, Mosyle, raw payloads

In a com.apple.security.scep payload:

Key Value
URL https://pki.example.com/scep/<endpoint-id>
Challenge The challenge password, or a dynamic challenge where the MDM supports one
Key Size 2048 or greater
Key Usage Digital signature and key encipherment
Subject Whatever your endpoint's subject pattern permits

Jamf Pro can fetch a unique challenge per device — see Jamf Pro. Kandji and Mosyle take a challenge in the payload, so use a shared secret or mint one-time challenges from automation.

Windows — Intune and MDM CSP

See Microsoft Intune for connecting the tenant. The critical detail is the URL:

✓  https://pki.example.com/scep/<endpoint-id>
✗  https://pki.example.com/scep/<endpoint-id>/pkiclient.exe

Do not add /pkiclient.exe; Windows appends it. Adding it produces /pkiclient.exe/pkiclient.exe and error 0x800700CE.

Workspace ONE UEM and Ivanti Neurons

Configure a generic SCEP certificate authority with the endpoint URL and the downloaded CA/RA bundle. Prefer one-time challenges; fall back to the shared secret only where the product cannot retrieve a unique challenge per device.

Policy sources

The endpoint decides The MDM profile decides
Certificate validity Subject and subject alternative names requested
Renewal window Key type and size
Which extended key usages may be requested Which of the permitted usages this profile asks for
Which subjects and names are acceptable When the device attempts renewal

SimpleSCEP ignores the MDM validity setting. Requests for unpermitted usages are rejected and recorded under Recent enrollments. See Issuance profiles and key usages.

Before rolling out to a fleet

  1. Enroll one device and confirm the certificate appears on the Certificates page with the subject and usages you expect.
  2. Revoke that certificate and confirm it appears on the CRL — see Revocation, CRL and OCSP.
  3. Check Recent enrollments for refusals before expanding the rollout.