Configuring Microsoft Intune in Cloudpath

The Simple Certificate Enrollment Protocol (SCEP) provisions new or renewed certificates to a device.
  1. Configure Microsoft® Azure based on the instructions provided in: https://learn.microsoft.com/en-us/mem/intune/protect/certificate-authority-add-scep-overview#set-up-third-party-ca-integration
  2. From the Cloudpath web interface, navigate to Certificate Authority > Manage Templates.
  3. Click the icon.
    The Certificate Template page is displayed.
  4. Navigate to the SCEP Keys tab.
  5. Under SCEP Keys, click Add SCEP Key.
    The Create SCEP Key page is displayed.
  6. Under the Validity Information section, set Challenge Password Type to Microsoft Intune.
    The following new fields are now displayed:
    • Microsoft Intune Tenant ID
    • Azure Application ID
    • Azure Application Key
    Populate these fields with the information retrieved from step 1 (App ID, Secret Key, and Tenant ID).

    Microsoft Intune Configuration

  7. Create a Trusted CA profile in Intune by following the instructions in: https://learn.microsoft.com/en-us/mem/intune/protect/certificates-trusted-root#create-trusted-certificate-profiles.
  8. Configure Intune SCEP Configuration by following the instructions in: https://learn.microsoft.com/en-us/mem/intune/protect/certificates-profile-scep.
    Configuring the Root CA may differ for different operating systems. For most operating systems, it is recommended to set Root CA to the Intermediate CA of the Certificate Template. For Android™, it is recommended to set Root CA of the Certificate Template's chain.
    Note: If you get an error during SCEP enrollment (for example, if the hash value is not correct), then it is recommended to set Root CA to the Root CA of the Certificate Template's chain.