> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/ja/use-cases.md).

# ユースケース

このページでは、あなたに **概要** の **一般的なユースケース** 当社の顧客が SCEPman を活用している一般的なユースケースやシナリオについてご案内することを目的としています。すべてのベンダーソリューションの細かな仕様までサポートすることはできませんが、この概要が、あまり一般的でない、あるいは特殊なユースケースで情報を圧迫することなく、SCEPman があなたのシナリオにも適しているかどうかを素早く判断する一助になれば幸いです。ご不明な点があれば、ぜひ [お問い合わせください](https://www.scepman.com/drop-a-question).

## セキュアな WiFi とネットワークアクセス

SCEPman によって発行された証明書は、WiFi、有線/LAN、VPN 向けの証明書ベースのネットワーク認証 (802.1X / EAP-TLS) に広く利用されています。通常は、RADIUS または RadSec プロトコルに対応したネットワークアクセス制御 (NAC) サービスと併用されます。このようなサービスには一般的に

* [RADIUSaaS](https://www.radius-as-a-service.com/)
* Aruba ClearPass
* Cisco ISE / Cisco ASA
* Azure VPN Gateway / Azure AlwaysOn VPN
* Fortinet FortiGate
* Palo Alto GlobalProtect

ノート PC、PC、Mac などの一般的なユーザー中心のクライアントデバイスに加えて、 **キオスク端末** POS やセルフレジシステム、スキャナー/バーコードガン、または顧客端末などにも、安全なネットワーク認証のために SCEPman の証明書が搭載されていることがよくあります。

## 証明書ベースの認証

SCEPman でユーザー認証証明書を TLS クライアント認証用に登録できます。これにより、次のような Web サイトやサービスへの認証が可能になります。

* 社内 Web アプリケーション
* [Windows](/ja/zheng-ming-shu-guan-li/api-certificates/api-enrollment/windows-server.md) または [Linux](/ja/zheng-ming-shu-guan-li/api-certificates/api-enrollment/linux-server.md) サーバー
* Microsoft 365
  * Exchange Online
  * Entra ID / Azure CBA（ [CRL サポート](/ja/scepman-gou-cheng/application-settings/crl.md)を含む）は、たとえば次のような要件で必要とされます。 [NIST 800-63, Rev. 4](https://www.nist.gov/identity-access-management/roadmap-nist-special-publication-800-63-4-digital-identity-guidelines)
* その他のクラウドサービス
* リモート デスクトップ (RDP) 接続
  * AVD
  * Windows サーバー管理 / PAWs

## TLS インスペクション

SCEPman は [サブ CA 証明書を発行できます](/ja/zheng-ming-shu-guan-li/certificate-master/sub-ca-certificate.md) ファイアウォール機器や次のようなサービスでの TLS インスペクション向けに

* [Azure Firewall](https://learn.microsoft.com/en-us/azure/firewall/premium-certificates)
* Global Secure Access (GSA)（[Microsoft Entra Internet Access](https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-transport-layer-security))
* その他のファイアウォール機器

## MDM ソリューション

関連する構成プロファイルの展開を自動化し、証明書を最新の状態に保つ（自動更新）ために、SCEPman を MDM ソリューションと併用することをお勧めします。SCEPman は Intune および Jamf Pro とネイティブに統合されますが、当社のお客様は他の MDM ソリューションと組み合わせて SCEPman を導入することにも成功しています。

以下の表は、最も一般的に使用されている MDM ソリューションの概要を示し、証明書失効がどのように/可能かどうかを示しています。

| MDM ソリューション                                                                             | サポート対象プラットフォーム                                                                                                                                                                   | 発行と自動更新                             | 自動失効                         | 手動失効                                                                               | リンク                                                                                                                                                                                                                                                                                                                                                                   |
| --------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------- | ---------------------------- | ---------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [Intune](/ja/zheng-ming-shu-guan-li/microsoft-intune.md)                                | <p>Windows<br>macOS<br>iOS</p><p>iPadOS<br>Android<br><a href="/ja/zheng-ming-shu-guan-li/api-certificates/self-service-enrollment/intune-managed-linux-client.md">Linux</a></p> | :ballot\_box\_with\_check:          | :ballot\_box\_with\_check:   | <p><span data-gb-custom-inline data-tag="emoji" data-code="2611">☑️</span><br></p> | [Microsoft Docs](https://docs.microsoft.com/en-us/mem/intune/protect/certificates-profile-scep)                                                                                                                                                                                                                                                                       |
| [Active Directory / グループ ポリシー (GPO)](/ja/zheng-ming-shu-guan-li/active-directory.md)    | Windows                                                                                                                                                                          | :ballot\_box\_with\_check:          |                              |                                                                                    |                                                                                                                                                                                                                                                                                                                                                                       |
| [Jamf Pro](/ja/zheng-ming-shu-guan-li/jamf.md)                                          | <p>macOS<br>iOS<br>iPadOS</p>                                                                                                                                                    | :ballot\_box\_with\_check:          | :ballot\_box\_with\_check:   | :ballot\_box\_with\_check:                                                         | [Jamf Technical Paper](https://docs.jamf.com/technical-papers/jamf-pro/scep-proxy/10.0.0/Introduction.html)                                                                                                                                                                                                                                                           |
| [Google Workspace](/ja/zheng-ming-shu-guan-li/static-certificates.md)                   | <p>ChromeOS<br>Android</p>                                                                                                                                                       | :ballot\_box\_with\_check:          | :ballot\_box\_with\_check:\* | :ballot\_box\_with\_check:                                                         | [Google サポート ドキュメント](https://support.google.com/chrome/a/answer/11053129?hl=en)                                                                                                                                                                                                                                                                                       |
| [Omnissa（旧 Airwatch / WorkspaceONE）](/ja/zheng-ming-shu-guan-li/static-certificates.md) | <p>macOS<br>iOS</p>                                                                                                                                                              | :ballot\_box\_with\_check: （自動更新なし） |                              | :ballot\_box\_with\_check:                                                         | [VMware サポート ドキュメント](https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/2011/Certificate_Authority_Integrations/GUID-EF7C4D44-9480-4AD1-91E3-EA4F02448F5A.html)                                                                                                                                                                                                      |
| [Mosyle](/ja/zheng-ming-shu-guan-li/static-certificates/mosyle.md)                      | <p>macOS</p><p>iOS<br>iPadOS</p>                                                                                                                                                 | :ballot\_box\_with\_check:          |                              | :ballot\_box\_with\_check:                                                         |                                                                                                                                                                                                                                                                                                                                                                       |
| [SOTI MobiControl](/ja/zheng-ming-shu-guan-li/static-certificates.md)                   | <p>Windows<br>macOS<br>iOS</p><p>iPadOS<br>Android<br>Ubuntu</p>                                                                                                                 | :ballot\_box\_with\_check:          |                              | :ballot\_box\_with\_check:                                                         | <p><a href="https://www.soti.net/mc/help/v14.1/en/console/reference/dialogs/globalsettings/certificates/certificate_authorities.html?hl=certificate%2Cauthority#globalsetting_certificate_authorities__genericscep">Soti ドキュメント - 外部 CA</a><br><a href="https://www.soti.net/mc/help/v14.1/en/console/system/certificates/add.html">Soti ドキュメント - SCEP プロファイル</a></p> |
| [Iru（旧 Kandji）](/ja/zheng-ming-shu-guan-li/static-certificates/kandji-1.md)             | <p>macOS<br>iOS<br>iPadOS</p>                                                                                                                                                    | :ballot\_box\_with\_check:          | :ballot\_box\_with\_check:\* | :ballot\_box\_with\_check:                                                         | [Kandji ドキュメント](https://support.kandji.io/support/solutions/articles/72000559782-scep-profile)                                                                                                                                                                                                                                                                        |
| [ManageEngine](/ja/zheng-ming-shu-guan-li/static-certificates.md)                       | <p>Windows<br>macOS<br>iOS</p><p>iPadOS<br>Android</p>                                                                                                                           | :ballot\_box\_with\_check:          |                              | :ballot\_box\_with\_check:                                                         | [ManageEngine ドキュメント](https://www.manageengine.com/mobile-device-management/help/certificate_management/mdm_integrating_generic_scep.html)                                                                                                                                                                                                                            |
| [Addigy](/ja/zheng-ming-shu-guan-li/static-certificates/addigy.md)                      | <p>macOS<br>iOS<br>iPadOS</p>                                                                                                                                                    | :ballot\_box\_with\_check:          | :ballot\_box\_with\_check:\* | :ballot\_box\_with\_check:                                                         | [Addigy ドキュメント](https://docs.addigy.com/)                                                                                                                                                                                                                                                                                                                             |

\*: ユーザーオブジェクトが Microsoft Entra ID (Azure AD) から同期されている場合にのみ、ユーザー型証明書で動作します。

## オンプレミスからクラウドへの移行

SCEPman はクラウドネイティブで汎用の PKI であるため、オンプレミスのインフラをクラウドへ移行する多くのお客様が、オンプレミスの Microsoft PKI (ADCS および NDES) を完全に置き換える目的で SCEPman を利用しています。SCEPman を使えば、これは次のようなエンドポイントデバイスで可能です。

* ドメイン参加済み
* ハイブリッド参加済み
* Entra ID 参加済み

## IoT デバイス

SCEPman は IoT デバイスに証明書を供給するために利用できます。さらに、SCEPman は ECC CA をサポートしており、計算リソースが限られたデバイスやバッテリー駆動のデバイスで、性能と電力効率に最適化された暗号アルゴリズムを利用できます。SCEPman の柔軟性により、有効期間の長い証明書を発行できるため、定期的な更新を必要とせずに長期間のオフライン運用が可能です。さらに、Microsoft Entra ID (Azure AD) ベースの認証を用いた SCEPman の REST API を活用することで、組立ライン上で便利に証明書を登録することもできます。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/ja/use-cases.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
