iOS/iPadOS
Last updated
Last updated
The following article describes how to deploy a device or/and user certificates for iOS and iPadOS devices. The deployment of the SCEPman Root Certificate is mandatory. Afterward you can choose between deploying only device, user or even both certificate types.
The basis for deploying SCEP certificates is to trust the root certificate of SCEPman. Therefore, you have to download the CA Root certificate and deploy it as a Trusted certificate profile via Microsoft Intune:
Note, that you have to use the same group for assigning the Trusted certificate and SCEP profile. Otherwise, the Intune deployment might fail.
With our stated settings, we fulfill Apples certificate requirements.
Please follow the instructions of Device certificates and take care of the following differences:
With our stated settings, we fulfill Apples certificate requirements
{{DeviceId}}: This ID is generated and used by Intune (Recommended) (requires SCEPman 2.0 or higher and to be set to Intune or AADAndIntune)
Important: iOS/iPadOS devices ignore the configuration of the validity period via Intune. Please make sure, to configure to a fixed value. We recommend 2 years, so you have to set this variable in SCEPman configuration to 730 days. But you can leave the certificate validity period setting to 1 year because Intune ignores it anyway. Important: Also note, that certificates on iOS/iPadOS are only renewed by Intune when the device is unlocked, online, syncing and in scope of the renewal threshold. If certificates are expired (e.g.: device was offline and/or locked for a long time), they won't be renewed any more. Therefore, we recommend to choose an higher value here.