> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/ja/zheng-ming-shu-guan-li/microsoft-intune/android.md).

# Android

Intune と SCEPman を使用して SCEP 経由で Android デバイスに証明書を展開します。

以下の記事では、Android にデバイス証明書またはユーザー証明書を展開する方法を説明します。Android の証明書展開は、Windows 10、macOS、iOS の証明書展開と似ています。

{% hint style="info" %}
Android には 2 つの異なるソリューション セットがあります。1 つは [ワーク プロファイル](https://developers.google.com/android/work/requirements/work-profile) （として知られる *個人所有のワーク プロファイル）* もう 1 つは [完全管理対象デバイス](https://developers.google.com/android/work/requirements/fully-managed-device) （別名 *Fully Managed、Dedicated、および Corporate-Owned Work Profile*）。どちらのシナリオでも、証明書構成プロファイルの設定は一貫しています。
{% endhint %}

{% hint style="info" %}
Android デバイス管理者管理は、Android デバイスを管理する方法として Android 2.2 でリリースされました。その後、Android 5 からは、より新しい Android Enterprise の管理フレームワークがリリースされました（Google Mobile Services に確実に接続できるデバイス向けです）。 **Google は、新しい Android リリースでの管理サポートを減らすことで、デバイス管理者管理からの移行を促進しています**。詳細については、 [MS. Intune の Android デバイス管理者サポートの縮小](https://techcommunity.microsoft.com/t5/intune-customer-success/decreasing-support-for-android-device-administrator/ba-p/1441935)
{% endhint %}

## ルート証明書

SCEP 証明書（デバイス証明書またはユーザー証明書）を展開するための前提は、SCEPman のルート証明書を信頼することです。したがって、CA ルート証明書をダウンロードし、次のものとして展開する必要があります。 **信頼された証明書** Microsoft Intune 経由のプロファイル:

* [ ] SCEPman ポータルから CA 証明書をダウンロードする

![](https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-9170eb0435726398eb43f6fac8abd0d5f35e8cc4%2FSCEPmanHomePage%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(2\)%20\(1\)%20\(2\).png?alt=media)

* [ ] Android Enterprise 用のプロファイルを、次の種類で作成します **信頼された証明書** Microsoft Intune で（Android デバイスの登録オプションに基づいて）

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2F2DS8ORZGsIam5n30wm78%2F2024-01-09%2015_24_48-Create%20a%20profile.png?alt=media&amp;token=1f67c895-0c97-4b18-9f2a-c5d9cde273df" alt=""><figcaption></figcaption></figure>

* [ ] 以前にダウンロードした **.cer ファイル**.
* [ ] これで、このプロファイルをデバイスに展開できます。割り当てには、すべてのユーザーおよび/またはすべてのデバイス、または専用グループを選択してください。

{% hint style="info" %}
注意: 次のものを使用する必要があります **割り当てに同じグループを** その **信頼された証明書** および **SCEP プロファイル**。そうしないと、Intune の展開が失敗する可能性があります。
{% endhint %}

{% hint style="warning" %}
一部の Android Enterprise 展開では、Intune の信頼済み証明書プロファイルに完全な証明機関チェーン（Root CA + Intermediate CA）が必要です。これは特に、中間 CA 証明書の更新後に重要で、Root CA のみを展開すると、SCEP ユーザー証明書または WLAN 証明書の展開が失敗する場合があります。
{% endhint %}

## デバイス証明書

* [ ] SCEPman ポータルを開き、下の URL をコピーします **Intune MDM**

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FaGrpTnexZ76xOot66Q8d%2F2024-01-09%2015_10_27.png?alt=media&amp;token=105d39c4-50b8-4fa2-9dfe-6ee87059b1d1" alt=""><figcaption></figcaption></figure>

* [ ] Android Enterprise 用のプロファイルを、次の種類で作成します **SCEP 証明書** Microsoft Intune で（再度、Android デバイスの登録オプションに基づいて）

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fd73QTNENVyCjfNXDRGVO%2F2024-01-09%2016_09_19-Create%20a%20SCEP%20profile.png?alt=media&amp;token=79df117e-3e45-4a5f-9427-9b0b49da7738" alt=""><figcaption></figcaption></figure>

* [ ] 説明どおりにプロファイルを構成します

<details>

<summary>証明書の種類: <code>デバイス</code></summary>

このセクションでは、デバイス証明書を設定します。

</details>

<details>

<summary>サブジェクト名の形式: <code>CN={{DeviceId}}</code> または <code>CN={{AAD_Device_ID}}</code></summary>

SCEPman は、件名の CN フィールドを使用してデバイスを識別し、証明書シリアル番号生成の種としても使用します。Microsoft Entra ID (Azure AD) と Intune では、2 つの異なる ID が提供されます:

* {{DeviceId}}: この ID は Intune によって生成され、使用されます **（推奨）。** （要 [#AppConfig:IntuneValidation:DeviceDirectory](/ja/scepman-gou-cheng/application-settings/scep-endpoints/intune-validation.md#appconfig-intunevalidation-devicedirectory) を **Intune** または **AADAndIntune**
* {{AAD\_Device\_ID}}: この ID は Microsoft Entra ID (Azure AD) によって生成され、使用されます。

必要に応じて他の RDN を追加できます（例: `CN={{DeviceId}}, O=Contoso, CN={{WiFiMacAddress}}`）。サポートされている変数は [Microsoft docs](https://learn.microsoft.com/en-us/mem/intune/protect/certificates-profile-scep#create-a-scep-certificate-profile).

</details>

<details>

<summary>サブジェクト代替名: <code>URI</code> 値:<code>IntuneDeviceId://{{DeviceId}}</code></summary>

```
IntuneDeviceId://{{DeviceId}}
```

URI フィールドは [Microsoft によって推奨されています](https://techcommunity.microsoft.com/t5/intune-customer-success/new-microsoft-intune-service-for-network-access-control/ba-p/2544696) NAC ソリューションが Intune デバイス ID に基づいてデバイスを識別するための:

必要に応じて、DNS などの他の SAN 値を追加できます。

</details>

<details>

<summary>証明書の有効期間: <code>1 年</code></summary>

証明書の有効期限が切れるまでの残り時間です。既定値は 1 年です。

SCEPman は、設定 [***AppConfig:ValidityPeriodDays***](/ja/scepman-gou-cheng/application-settings/certificates.md#appconfig-validityperioddays)で構成された最大値に証明書の有効期間を制限しますが、それ以外は要求で構成された有効期間を使用します。

</details>

<details>

<summary>キー使用法: <code>デジタル署名</code> および <code>鍵の暗号化</code></summary>

両方の暗号操作を有効にしてください。

</details>

<details>

<summary>キー サイズ（ビット）: <code>4096</code></summary>

SCEPman は 4096 ビットをサポートしています。

</details>

<details>

<summary>ルート証明書: <code>前の手順のプロファイル</code></summary>

次の \[ から Intune プロファイルを選択してください[#root-certificate](#root-certificate "mention")]\(android.md#root-certificate)。

次のものを使用している場合 [Intermediate CA](/ja/scepman-nodepuroi/intermediate-certificate.md)、中間 CA ではなく、Root CA の信頼済み証明書プロファイルを選択する必要があります！

</details>

<details>

<summary>拡張キー使用法: <code>Client Authentication, 1.3.6.1.5.5.7.3.2</code></summary>

次を選択してください **Client Authentication (1.3.6.1.5.5.7.3.2)** の下の **定義済みの値**。他のフィールドは自動的に入力されます。

</details>

<details>

<summary>更新しきい値（%）: <code>20</code></summary>

この値は、デバイスが証明書を更新できる時期を定義します（既存証明書の残存有効期間に基づきます）。 **証明書の有効期間** の下の注意を読み、デバイスが長期間にわたって証明書を更新できる適切な値を選択してください。20% を指定すると、有効期間が 1 年の証明書を持つデバイスは、有効期限の 73 日前に更新を開始できます。

</details>

<details>

<summary>SCEP サーバー URL: SCEPman ポータルを開き、 <a href="#device-certificates">#Intune MDM</a></summary>

**例**

```
https://scepman.contoso.com/certsrv/mscep/mscep.dll
```

</details>

### **例**

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2F6rhuZgf1t97jdoUukn7I%2F2024-01-11%2011_04_19-SCEP%20certificate%20-%20AndroidEnterpriseDeviceCert.png?alt=media&amp;token=50626cb1-717f-40e0-a26d-efcfbf4ec526" alt=""><figcaption></figcaption></figure>

## ユーザー証明書

次の手順に従ってください [#デバイス証明書](#device-certificates) および、次の違いに注意してください:

<details>

<summary>証明書の種類: <code>ユーザー</code></summary>

このセクションでは、ユーザー証明書を設定しています。

</details>

<details>

<summary>サブジェクト名の形式: <code>CN={{UserName}},E={{EmailAddress}}</code></summary>

必要に応じて RDN を定義できます。サポートされている変数は [Microsoft docs](https://docs.microsoft.com/en-us/mem/intune/protect/certificates-profile-scep#create-a-scep-certificate-profile)に一覧があります。ユーザー名（例: janedoe）とメールアドレス（例: <janedoe@contoso.com>）を基本設定として含めることを推奨します。

</details>

<details>

<summary>サブジェクト代替名: <code>(UPN)</code>値: <code>{{UserPrincipalName}}</code></summary>

あなたは **は** ユーザー プリンシパル名をサブジェクト代替名として追加します。 **型がユーザー プリンシパル名（UPN）のサブジェクト代替名として '{{UserPrincipalName}}' を追加します。** これにより、SCEPman は AAD のユーザー オブジェクトに証明書を関連付けることができます。

必要に応じて、メール アドレスなどの他の SAN 値を追加できます。

</details>

{% hint style="info" %}
次のものが必要です **サブジェクト代替名** を **SCEP 証明書、ユーザー種別**。SAN がないと、会社の Wi-Fi にアクセスできません。
{% endhint %}

### **例**

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2F7tlHRUVO5ebSmQjZ1uRu%2F2024-01-11%2010_59_48-SCEP%20certificate%20-%20AndroidEnterpriseUserCert.png?alt=media&amp;token=6d860b78-8f70-4606-88ca-cf5f259cd560" alt=""><figcaption></figcaption></figure>

## 証明書の確認

Android デバイスで証明書を正しく展開するために、2 つの方法があります:

* 新しい Android バージョン（例: 14）では、証明書（ユーザー証明書および信頼済み証明書）を次の場所から確認できます。 **設定** > **セキュリティとプライバシー**
* 次のようなサードパーティ アプリを使用して [X509 Certificate Viewer Tool](https://play.google.com/store/apps/details?id=com.rdupletlabs.certificateviewer)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/ja/zheng-ming-shu-guan-li/microsoft-intune/android.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
