> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/de/use-cases.md).

# Anwendungsfälle

Diese Seite soll Ihnen einen **Überblick** über **häufige Anwendungsfälle** und Szenarien geben, für die unsere Kunden SCEPman einsetzen. Obwohl wir keine Unterstützung für die Feinheiten jeder einzelnen Anbieterlösung bieten können, hoffen wir, dass dieser Überblick Ihnen hilft, schnell zu beurteilen, ob SCEPman auch für Ihr Szenario geeignet sein könnte - ohne Sie mit weniger gängigen oder sogar exotischen Anwendungsfällen zu überfordern. Wenn Sie unsicher sind, dann [schreiben Sie uns einfach eine Frage](https://www.scepman.com/drop-a-question).

## Sicheres WLAN und Netzwerkzugriff

Von SCEPman ausgestellte Zertifikate werden häufig für die zertifikatbasierte Netzwerkauthentifizierung (802.1X / EAP-TLS) für WLAN, kabelgebunden/LAN und VPN verwendet, typischerweise zusammen mit einem Network-Access-Control-(NAC)-Dienst, der das RADIUS- oder RadSec-Protokoll spricht. Solche Dienste sind üblicherweise

* [RADIUSaaS](https://www.radius-as-a-service.com/)
* Aruba ClearPass
* Cisco ISE / Cisco ASA
* Azure VPN Gateway / Azure AlwaysOn VPN
* Fortinet FortiGate
* Palo Alto GlobalProtect

Zusätzlich zu typischen benutzerorientierten Endgeräten wie Laptops, PCs oder Macs werden **Kiosk-Geräte** wie Kassensysteme oder Self-Checkout-Systeme, Scanner-/Barcode-Handscanner oder Kundenterminals oft mit Zertifikaten von SCEPman für eine sichere Netzwerkauthentifizierung ausgestattet.

## Zertifikatbasierte Authentifizierung

Sie können Benutzer-Authentifizierungszertifikate mit SCEPman für die TLS-Clientauthentifizierung ausrollen. Dies ermöglicht die Authentifizierung bei Websites oder Diensten wie

* Interne Webanwendungen
* [Windows](/de/zertifikatsverwaltung/api-certificates/api-enrollment/windows-server.md) oder [Linux](/de/zertifikatsverwaltung/api-certificates/api-enrollment/linux-server.md) Servern
* Microsoft 365
  * Exchange Online
  * Azure Active Directory (AAD) / Azure CBA (einschließlich [CRL-Unterstützung](/de/scepman-konfiguration/application-settings/crl.md)) wie z. B. erforderlich durch [NIST 800-63, Rev. 4](https://www.nist.gov/identity-access-management/roadmap-nist-special-publication-800-63-4-digital-identity-guidelines)
* Andere Cloud-Dienste
* Remote-Desktop-(RDP)-Verbindungen
  * AVD
  * Windows-Serveradministration / PAWs

## TLS-Inspektion

SCEPman kann [Sub-CA-Zertifikate ausstellen](/de/zertifikatsverwaltung/certificate-master/sub-ca-certificate.md) für TLS-Inspektion auf Firewall-Appliances und Diensten wie

* [Azure Firewall](https://learn.microsoft.com/en-us/azure/firewall/premium-certificates)
* Global Secure Access (GSA) ([Microsoft Entra Internet Access](https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-transport-layer-security))
* Andere Firewall-Appliances

## MDM-Lösungen

Zur Automatisierung der Bereitstellung relevanter Konfigurationsprofile und um Zertifikate auf dem neuesten Stand zu halten (automatische Verlängerung), empfehlen wir, SCEPman zusammen mit einer MDM-Lösung zu verwenden. Während SCEPman sich nativ in Microsoft Endpoint Manager/Intune und Jamf Pro integriert, haben unsere Kunden SCEPman erfolgreich zusammen mit anderen MDM-Lösungen eingesetzt.

Die folgende Tabelle bietet einen Überblick über die am häufigsten verwendeten MDM-Lösungen und zeigt, wie/ob ein Zertifikatswiderruf möglich ist.

| MDM-Lösung                                                                                        | Unterstützte Plattformen                                                                                                      | Ausstellung & automatische Verlängerung                      | Automatischer Widerruf       | Manueller Widerruf                                                                 | Links                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------ | ---------------------------- | ---------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><a href="/pages/e3c41e3d155553a007cb75e3182a936e3d908f2f">Intune /<br>Endpoint Manager</a></p> | <p>Windows<br>macOS<br>iOS</p><p>iPadOS<br>Android<br><a href="/pages/028673eb39b6086496ee57aebcb697e42caf8b34">Linux</a></p> | :ballot\_box\_with\_check:                                   | :ballot\_box\_with\_check:   | <p><span data-gb-custom-inline data-tag="emoji" data-code="2611">☑️</span><br></p> | [Microsoft Docs](https://docs.microsoft.com/en-us/mem/intune/protect/certificates-profile-scep)                                                                                                                                                                                                                                                                                  |
| [Active Directory / Gruppenrichtlinie (GPO)](/de/zertifikatsverwaltung/active-directory.md)       | Windows                                                                                                                       | :ballot\_box\_with\_check:                                   |                              |                                                                                    |                                                                                                                                                                                                                                                                                                                                                                                  |
| [Jamf Pro](/de/zertifikatsverwaltung/jamf.md)                                                     | <p>macOS<br>iOS<br>iPadOS</p>                                                                                                 | :ballot\_box\_with\_check:                                   | :ballot\_box\_with\_check:   | :ballot\_box\_with\_check:                                                         | [Jamf-Fachpapier](https://docs.jamf.com/technical-papers/jamf-pro/scep-proxy/10.0.0/Introduction.html)                                                                                                                                                                                                                                                                           |
| [GSuite / Google Workspace](/de/zertifikatsverwaltung/static-certificates.md)                     | <p>ChromeOS<br>Android</p>                                                                                                    | :ballot\_box\_with\_check:                                   | :ballot\_box\_with\_check:\* | :ballot\_box\_with\_check:                                                         | [Google Support-Dokumente](https://support.google.com/chrome/a/answer/11053129?hl=en)                                                                                                                                                                                                                                                                                            |
| [Airwatch / WorkspaceONE UEM](/de/zertifikatsverwaltung/static-certificates.md)                   | <p>macOS<br>iOS</p>                                                                                                           | :ballot\_box\_with\_check: (keine automatische Verlängerung) |                              | :ballot\_box\_with\_check:                                                         | [VMware Support-Dokumente](https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/2011/Certificate_Authority_Integrations/GUID-EF7C4D44-9480-4AD1-91E3-EA4F02448F5A.html)                                                                                                                                                                                                           |
| [Mosyle](/de/zertifikatsverwaltung/static-certificates/mosyle.md)                                 | <p>macOS</p><p>iOS<br>iPadOS</p>                                                                                              | :ballot\_box\_with\_check:                                   |                              | :ballot\_box\_with\_check:                                                         |                                                                                                                                                                                                                                                                                                                                                                                  |
| [SOTI MobiControl](/de/zertifikatsverwaltung/static-certificates.md)                              | <p>Windows<br>macOS<br>iOS</p><p>iPadOS<br>Android<br>Ubuntu</p>                                                              | :ballot\_box\_with\_check:                                   |                              | :ballot\_box\_with\_check:                                                         | <p><a href="https://www.soti.net/mc/help/v14.1/en/console/reference/dialogs/globalsettings/certificates/certificate_authorities.html?hl=certificate%2Cauthority#globalsetting_certificate_authorities__genericscep">Soti-Dokumente - Externe CA</a><br><a href="https://www.soti.net/mc/help/v14.1/en/console/system/certificates/add.html">Soti-Dokumente - SCEP-Profil</a></p> |
| [Kandji](/de/zertifikatsverwaltung/static-certificates/kandji-1.md)                               | <p>macOS<br>iOS<br>iPadOS</p>                                                                                                 | :ballot\_box\_with\_check:                                   | :ballot\_box\_with\_check:\* | :ballot\_box\_with\_check:                                                         | [Kandji-Dokumente](https://support.kandji.io/support/solutions/articles/72000559782-scep-profile)                                                                                                                                                                                                                                                                                |
| [ManageEngine](/de/zertifikatsverwaltung/static-certificates.md)                                  | <p>Windows<br>macOS<br>iOS</p><p>iPadOS<br>Android</p>                                                                        | :ballot\_box\_with\_check:                                   |                              | :ballot\_box\_with\_check:                                                         | [ManageEngine-Dokumente](https://www.manageengine.com/mobile-device-management/help/certificate_management/mdm_integrating_generic_scep.html)                                                                                                                                                                                                                                    |

\*: Funktioniert nur mit Zertifikaten vom Benutzertyp, wenn die Benutzerobjekte aus Microsoft Entra ID (Azure AD) synchronisiert werden.

## Migration von On-Premises in die Cloud

Da SCEPman eine cloud-native und universelle PKI ist, nutzen viele unserer Kunden, die ihre On-Premises-Infrastruktur in die Cloud migrieren, SCEPman, um ihre lokale Microsoft-PKI (ADCS und NDES) vollständig zu ersetzen. Mit SCEPman ist dies für Endgeräte möglich, die

* Domänen-verbunden,
* hybrid verbunden oder&#x20;
* Entra ID-verbunden sind.

## IoT-Geräte

SCEPman kann genutzt werden, um IoT-Geräte mit Zertifikaten zu versorgen. Daher unterstützt SCEPman eine ECC-CA, die leistungs- und energieoptimierte kryptografische Algorithmen auf Geräten mit begrenzten Rechenressourcen oder auf batteriebetriebenen Geräten ermöglicht. Die Flexibilität von SCEPman unterstützt die Ausstellung von Zertifikaten mit langen Gültigkeitszeiträumen und ermöglicht einen langfristigen Offline-Betrieb ohne die Notwendigkeit, Zertifikate regelmäßig zu erneuern. Darüber hinaus können Zertifikate auf einer Montagelinie bequem ausgerollt werden, indem SCEPmans REST-API mit einer auf Microsoft Entra ID (Azure AD) basierenden Authentifizierung genutzt wird.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/de/use-cases.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
