Protocols
MDM configuration
SCEP configuration for Apple, Windows, and other MDM platforms.
Configure the MDM with the endpoint URL and its CA bundle. Use separate endpoints for populations with different validity, naming, or key-usage requirements.
Deploy the CA chain in the same device profile as the SCEP payload. A device that does not trust the issuer will enroll and then fail to use the certificate for anything.
Apple — Jamf Pro, Kandji, Mosyle, raw payloads
In a com.apple.security.scep payload:
| Key | Value |
|---|---|
| URL | https://pki.example.com/scep/<endpoint-id> |
| Challenge | The challenge password, or a dynamic challenge where the MDM supports one |
| Key Size | 2048 or greater |
| Key Usage | Digital signature and key encipherment |
| Subject | Whatever your endpoint's subject pattern permits |
Jamf Pro can fetch a unique challenge per device — see Jamf Pro. Kandji and Mosyle take a challenge in the payload, so use a shared secret or mint one-time challenges from automation.
Windows — Intune and MDM CSP
See Microsoft Intune for connecting the tenant. The critical detail is the URL:
✓ https://pki.example.com/scep/<endpoint-id>
✗ https://pki.example.com/scep/<endpoint-id>/pkiclient.exe
Do not add /pkiclient.exe; Windows appends it. Adding it produces /pkiclient.exe/pkiclient.exe and error 0x800700CE.
Workspace ONE UEM and Ivanti Neurons
Configure a generic SCEP certificate authority with the endpoint URL and the downloaded CA/RA bundle. Prefer one-time challenges; fall back to the shared secret only where the product cannot retrieve a unique challenge per device.
Policy sources
| The endpoint decides | The MDM profile decides |
|---|---|
| Certificate validity | Subject and subject alternative names requested |
| Renewal window | Key type and size |
| Which extended key usages may be requested | Which of the permitted usages this profile asks for |
| Which subjects and names are acceptable | When the device attempts renewal |
SimpleSCEP ignores the MDM validity setting. Requests for unpermitted usages are rejected and recorded under Recent enrollments. See Issuance profiles and key usages.
Before rolling out to a fleet
- Enroll one device and confirm the certificate appears on the Certificates page with the subject and usages you expect.
- Revoke that certificate and confirm it appears on the CRL — see Revocation, CRL and OCSP.
- Check Recent enrollments for refusals before expanding the rollout.