Skip to main content

Create a trusted certificate profile in Intune for Windows

ROLE REQUIRED

Intune Administrator (minimum)

This procedure creates the trusted certificate profile and SCEP certificate profile in Intune required to deploy the Okta device trust certificate to macOS devices.

BEFORE YOU BEGIN

As part of ZeroTek's Okta Device Trust Setup guide, this procedure assumes you have completed Configure Okta as a certificate authority, including downloading the x.509 certificate. Only complete this procedure if the environment includes Windows devices.


Create a trusted certificate profile

  1. In the Microsoft Intune admin center, click Devices.

  2. Under By platform, click Windows.

  3. Click Configuration profiles.

  4. On the Policies tab, click Create > New Policy.

  5. Under Platform, select Windows 10 and later.

  6. Under Profile type, select Templates.

  7. Click Trusted certificate and click Create.

  8. Type a name for the certificate β€” our example uses Trusted Cert for Windows Intune in Okta β€” and click Next.

  9. Under Configuration settings, click the browse folder icon.

  10. Browse to and upload the x.509 certificate you downloaded from Okta, then click Open.

  11. From the Destination store dropdown, select Computer certificate store - Intermediate, then click Next.

  12. Add the user group in scope and click Next.

  13. In the Applicability Rules tab, click Next (no changes required).

  14. Click Create and confirm the new configuration profile appears in the list.

Create a SCEP profile in Intune

  1. In the Microsoft Intune admin center, navigate to Devices > Windows and click Create > New Policy.

  2. Under Platform, select Windows 10 and later.

  3. Create a profile: Under Profile type, select Templates.

  4. Click SCEP certificate and click Create.

  5. Type a name for the policy such as "Windows SCEP profile" and click Next.

  6. In the Configuration settings tab, specify the following:

    • Certificate type: User

    • Subject name format: CN={{UserName}} ManagementAttestation{{AAD_Device_ID}}

  7. Set the following values, then click Root Certificate:

    • Key storage provider: Enroll to Trusted Platform Module (TPM) KSP if present, otherwise...

    • Key usage: Digital signature

    • Key size: 2048

    • Hash algorithm: SHA-2

  8. Select the trusted certificate profile created earlier in this procedure and click OK.

  9. Under Predefined values, select Client Authentication.

  10. Paste the SCEP Server URL generated from Okta, then click Next.

  11. Add the same user group you added in Step 12, click Next, then on the final screen click Review + create.

NEXT STEPS


Need help? Contact ZeroTek Support at [email protected].

Did this answer your question?