Skip to main content

Create a trusted certificate profile in Intune for Mac

ROLE REQUIRED

Intune Administrator (minimum)

This procedure creates the trusted certificate profile and SCEP certificate profile in Intune required to deploy the Okta device trust certificate to macOS devices.

BEFORE YOU BEGIN

As part of ZeroTek's Okta Device Trust Setup guide, this procedure assumes you have completed Configure Okta as a certificate authority, including downloading the x.509 certificate. Only complete this procedure if the environment includes macOS devices.

Create a trusted certificate profil

  1. In the Microsoft Intune admin center, click Devices in the left menu.

  2. Under By platform, click macOS.

  3. Click Configuration profiles.

  4. On the Policies tab, click + Create > New Policy.

  5. Create a profile: Under Profile type, select Templates. Under Trusted certificate, select Trusted certificate and click Create.

  6. Type a name for the certificate, such as "Trusted Cert for Mac Intune in Okta", and click Next.

  7. Under Configuration settings, click the browse folder icon, upload the x.509 certificate you downloaded from Okta, and click Open. Click Next.

  8. Add the user group in scope and click Next.

  9. Click Create and confirm the new configuration profile appears in the list.

Create a SCEP profile in Intune

  1. From the Microsoft Intune admin center, navigate to Devices > macOS and click Create > New Policy.

  2. Specify the following, then click Create:

    • Profile type: Templates

    • Template name: SCEP certificate

  3. Type a name for the policy, such as "Mac SCEP profile", and click Next.

  4. In the Configuration settings tab, specify the following:

    • Certificate type: User

    • Subject name format: CN={{UserPrincipalName}}

    • Key usage: Digital Signature

    • Key size: 2048

    • Root Certificate: Select the trusted certificate profile created earlier

  5. Paste the SCEP Server URL generated from Okta, then click Next.

  6. Add the same user group you added above in Step 8, click Next, then click Review + create.

NEXT STEPS

If you have created the required trusted certificate profiles in Intune, it's time to Activate endpoint integration for Windows devices in Okta.


Need help? Contact ZeroTek Support at [email protected].

Did this answer your question?