> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/ja/zheng-ming-shu-guan-li/microsoft-intune/macos.md).

# macOS

次の記事では、macOS デバイスにデバイス証明書および/またはユーザー証明書を展開する方法を説明します。SCEPman Root Certificate の展開は必須です。その後、デバイス証明書のみ、ユーザー証明書のみ、または両方の証明書タイプを展開するかを選択できます。

{% hint style="warning" %}
macOS は、実際の SCEP 証明書プロファイルに加えて、SCEP プロファイルが参照されている各デバイス構成プロファイルごとに個別のクライアント認証証明書を登録することに注意してください。注を参照してください [こちら](https://learn.microsoft.com/en-us/intune/intune-service/protect/certificates-profile-scep#assign-the-certificate-profile)
{% endhint %}

## ルート証明書

SCEP 証明書を展開するための基本は、SCEPman のルート証明書を信頼することです。そのため、CA ルート証明書をダウンロードし、次のように展開する必要があります。 **信頼された証明書** Microsoft Intune 経由のプロファイル:

* [ ] SCEPman ポータルから CA 証明書をダウンロードします:

![](/files/b5de1a398b2e8c184245a65debd676ae589dd709)

* [ ] macOS 用のプロファイルを、次の種類で作成します **信頼された証明書** を Microsoft Intune で:

![](/files/1e10355451eab753ed15c24ba364cfbd1e112369)

* [ ] 以前にダウンロードした **.cer ファイル**.
* [ ] これで、このプロファイルをデバイスに展開できます。割り当てには、すべてのユーザーおよび/またはすべてのデバイス、または専用グループを選択してください。

{% hint style="info" %}
なお、使用する必要があるのは **割り当てに同じグループを** その **信頼された証明書** および **SCEP プロファイル**。そうしないと、Intune の展開に失敗する可能性があります。
{% endhint %}

## デバイス証明書

* [ ] SCEPman ポータルを開き、次の項目の下にある URL をコピーします **Intune MDM**:

![](/files/186eb2bf1fe5b8ad27abfeea08007b3e1ceacf92)

* [ ] macOS 用のプロファイルを、次の種類で作成します **SCEP 証明書** を Microsoft Intune で:

![](/files/4566f8d668d9861d5a17ea241051690d52332acb)

* [ ] 次のようにプロファイルを構成します:

<details>

<summary>証明書の種類: <code>デバイス</code></summary>

このセクションでは、デバイス証明書を設定します。

</details>

<details>

<summary>サブジェクト名の形式: <code>CN={{DeviceName}}</code> または <code>CN={{DeviceId}}</code> または <code>CN={{AAD_Device_ID}}</code></summary>

**推奨:** 使用する `{{DeviceName}}`を CN RDN に使用すると、デバイス上で証明書の意味のある名前になり、証明書を検索するときにも便利です。

**オプション:** 次のように構成されている場合 `CN={{DeviceId}}` または `CN={{AAD_Device_ID}}`, SCEPman はサブジェクト名の CN フィールドを使用してデバイスを識別し、証明書シリアル番号生成のシードとして使用します。Microsoft Entra ID (Azure AD) と Intune は 2 種類の ID を提供します:

* `{{DeviceId}}`: この ID は Intune によって生成され、使用されます。\
  \
  (次の設定が必要です [Intune 検証](/ja/scepman-no/application-settings/scep-endpoints/intune-validation.md#appconfig-intunevalidation-devicedirectory) を **Intune** または **AADAndIntune**)
* `{{AAD_Device_ID}}`: この ID は Microsoft Entra ID (Azure AD) によって生成され、使用されます。

次のいずれも `CN={{DeviceId}}` も `CN={{AAD_Device_ID}}` が CN フィールドに使用されない場合（例: `CN={{DeviceName}})`、SCEPman は Intune デバイス ID（`(URI) 値:` `IntuneDeviceId://{{DeviceId}}`）に基づいて、サブジェクト代替名（SAN）内の値を使用してデバイスを識別します。

**重要:** CN フィールドの選択は、 [証明書の自動失効動作](/ja/zheng-ming-shu-guan-li/manage-certificates.md#automatic-revocation) に影響し、Intune で管理されているデバイスに発行された証明書に反映されます。

必要に応じて他の RDN を追加できます（例: `CN={{DeviceId}}, O=Contoso, CN={{WiFiMacAddress}}`）。サポートされている変数は [Microsoft docs](https://docs.microsoft.com/en-us/mem/intune/protect/certificates-profile-scep#create-a-scep-certificate-profile).

</details>

<details>

<summary>サブジェクト代替名: <code>URI</code> 値:<code>IntuneDeviceId://{{DeviceId}}</code></summary>

URI フィールドは [Microsoft によって推奨されています](https://techcommunity.microsoft.com/t5/intune-customer-success/new-microsoft-intune-service-for-network-access-control/ba-p/2544696) NAC ソリューションが、Intune デバイス ID に基づいてデバイスを識別するためのものです。

```
IntuneDeviceId://{{DeviceId}}
```

この **URI フィールドは必須です** 次のいずれも `CN={{DeviceId}}` も `CN={{AAD_Device_ID}}` が **サブジェクト名の形式** フィールドに使用されていない場合。

必要に応じて、DNS などの他の SAN 値を追加できます。

</details>

<details>

<summary>証明書の有効期間: <code>1 年</code></summary>

<mark style="color:オレンジ;">**重要:**</mark> <mark style="color:オレンジ;">macOS デバイスは、Intune 経由の有効期間の設定を無視します。必ず次を構成してください</mark> [証明書](/ja/scepman-no/application-settings/certificates.md#appconfig-validityperioddays) <mark style="color:オレンジ;">固定値に。証明書の有効期間設定はどうせ無視されるため、1 年のままでもかまいません。</mark>\
\ <mark style="color:オレンジ;">**重要:**</mark> <mark style="color:オレンジ;">また、</mark> <mark style="color:オレンジ;">**macOS の証明書は、次の場合にのみ更新されます**</mark> <mark style="color:オレンジ;">Intune によって、デバイスが</mark> <mark style="color:オレンジ;">**ロック解除済み、オンライン、同期中で、更新しきい値の範囲内にある場合**</mark><mark style="color:オレンジ;">。証明書の有効期限が切れている場合（例: デバイスが長時間オフラインおよび/またはロックされていた場合）、それ以降は更新されません。そのため、ここではより高い値を選ぶことをお勧めします。</mark>

</details>

<details>

<summary>キー使用法: <code>デジタル署名</code> および <code>キー暗号化</code></summary>

両方の暗号操作を有効にしてください。

</details>

<details>

<summary>キー サイズ（ビット）: <code>2048</code></summary>

SCEPman は 2048 ビットをサポートしています。

</details>

<details>

<summary>ルート証明書: <code>前の手順のプロファイル</code></summary>

次から Intune プロファイルを選択してください [#ルート証明書](#root-certificate)

</details>

<details>

<summary>拡張キー使用法: <code>Client Authentication, 1.3.6.1.5.5.7.3.2</code></summary>

次を選択してください **Client Authentication (1.3.6.1.5.5.7.3.2)** の下の **定義済みの値**。他のフィールドは自動的に入力されます。

<mark style="color:オレンジ;">**重要:**</mark> <mark style="color:オレンジ;">macOS デバイスは、次以外の拡張キー使用法 (EKU) をサポートしていません</mark> <mark style="color:オレンジ;">`クライアント認証`</mark> <mark style="color:オレンジ;">。つまり、このプロファイルで構成された他の EKU はすべて無視されます。</mark>

</details>

<details>

<summary>更新しきい値（%）: <code>50</code></summary>

この値は、デバイスが証明書を更新できるタイミング（既存証明書の残り有効期間に基づく）を定義します。次の項目の下にある注をお読みください **証明書の有効期間** そして、デバイスが長期間にわたって証明書を更新できる適切な値を選択してください。50% の値にすると、有効期間 1 年の証明書を持つデバイスは、有効期限の 182 日前に更新を開始できます。

</details>

<details>

<summary>SCEP サーバー URL: SCEPman ポータルを開き、 <a href="#device-certificates"><strong>Intune MDM</strong></a></summary>

**例**

```
https://scepman.contoso.com/certsrv/mscep/mscep.dll
```

</details>

{% hint style="info" %}
上記の設定により、私たちは次を満たします [Apple の証明書要件](https://support.apple.com/en-us/HT210176).
{% endhint %}

### 例

<figure><img src="/files/130a64709835c32d26a54d7a57c2ba95b94bd539" alt=""><figcaption></figcaption></figure>

* [ ] これで、このプロファイルをデバイスに展開できます。割り当てには、信頼された証明書プロファイルと同じグループを選択してください。

## ユーザー証明書

次のセクションでは、macOS X 10.12（以降）のデバイスで、Intune の証明書プロファイルを使用してユーザー証明書を展開する方法を説明します。

{% hint style="warning" %}
ご注意ください: SCEP プロトコルを通じてプロビジョニングされた証明書は、種類（ユーザーまたはデバイス）にかかわらず、常にデバイスのシステムキーチェーン（System store）に格納されます。

サードパーティ製アプリケーションがそのような証明書へのアクセスを必要とする場合（例: サードパーティ製 VPN クライアント）、次のスライダーを **すべてのアプリに秘密鍵へのアクセスを許可** キーチェーン内の項目は次に設定する必要があります **有効**.
{% endhint %}

次の手順に従ってください [#デバイス証明書](#device-certificates) および、次の違いに注意してください:

<details>

<summary>証明書の種類: <code>ユーザー</code></summary>

このセクションでは、ユーザー証明書を設定しています。

</details>

<details>

<summary>サブジェクト名の形式: <code>CN={{UserName}},E={{EmailAddress}}</code></summary>

必要に応じて RDN を定義できます。サポートされている変数は [Microsoft docs](https://docs.microsoft.com/en-us/mem/intune/protect/certificates-profile-scep#create-a-scep-certificate-profile)に一覧があります。ユーザー名（例: janedoe）とメールアドレス（例: <janedoe@contoso.com>）を基本設定として含めることを推奨します。

</details>

<details>

<summary>サブジェクト代替名: <code>UPN</code> 値:<code>{{UserPrincipalName}}</code></summary>

SCEPman は、SAN 内の UPN をユーザーの識別と、証明書のシリアル番号生成のシードとして使用します（例: <janedoe@contoso.com>）。\
\
メールアドレスのような他の SAN 値は、必要に応じて追加できます。

</details>

{% hint style="info" %}
上記の設定により、私たちは次を満たします [Apple の証明書要件](https://support.apple.com/en-us/HT210176)
{% endhint %}

### 例

![](/files/52a750683402c98d57c671199f7ff8526e1d25ff)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/ja/zheng-ming-shu-guan-li/microsoft-intune/macos.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
