Network Device Enrollment Service. Part of AD CS, it processes SCEP certificate requests for a Microsoft certification authority, so Intune SCEP profiles using such a CA depend on it as well as on the Certificate Connector.
Also called Network Device Enrollment Service.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains NDES in context, with comparison tables and the common traps.
Terms in this definition
- AD CS
Short for Active Directory Certificate Services, a Windows Server role that operates a private certificate authority. Because the certificates it issues are not publicly trusted, services needing a public CA, such as Front Door bring-your-own-certificate, refuse them.
- SCEP
A protocol in which a device creates its own private key and asks for a certificate. In Intune, SCEP profiles depend on either Microsoft Cloud PKI or NDES alongside the Certificate Connector.
- Certificate
Key Vault object holding an X.509 certificate, whose associated key and secret are managed alongside it.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
Related terms
- Cloud PKI
An Intune Suite service that hosts root and issuing CAs, along with their AIA and CRL endpoints, in the cloud. It issues SCEP certificates straight to Intune-managed devices, so neither a certificate connector nor NDES is needed.