A protocol in which a device creates its own private key and asks for a certificate. In Intune, SCEP profiles depend on either Microsoft Cloud PKI or NDES alongside the Certificate Connector.
Also called Simple Certificate Enrollment Protocol.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains SCEP in context, with comparison tables and the common traps.
Terms in this definition
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - Certificate
Key Vault object holding an X.509 certificate, whose associated key and secret are managed alongside it.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- Cloud PKI
An Intune Suite service that hosts root and issuing CAs, along with their AIA and CRL endpoints, in the cloud. It issues SCEP certificates straight to Intune-managed devices, so neither a certificate connector nor NDES is needed.
- NDES
Network Device Enrollment Service. Part of AD CS, it processes SCEP certificate requests for a Microsoft certification authority, so Intune SCEP profiles using such a CA depend on it as well as on the Certificate Connector.
Related terms
- Subject alternative name
The part of a certificate (SAN) that names each host it is good for. Microsoft Tunnel Gateway needs its FQDN or IP address there, and SCEP or PKCS profiles can supply extra values.
- Trusted certificate profile
Delivers a root or intermediate CA certificate via Intune, so certificates from that CA are accepted. Target it at whichever groups also get dependent SCEP or PKCS profiles.