Skip to content

Commit 734d0d6

Browse files
authored
Merge pull request #2727 from schwerdti/patch-1
Renewal behaviour on iOS/iPadOS and macOS
2 parents 0c3c3b1 + 66b4f42 commit 734d0d6

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

memdocs/intune/protect/certificates-profile-scep.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -274,6 +274,9 @@ Devices that run Android Enterprise might require a PIN before SCEP can provisio
274274
- **Renewal threshold (%)**:
275275

276276
Enter the percentage of the certificate lifetime that remains before the device requests renewal of the certificate. For example, if you enter 20, the renewal of the certificate will be attempted when the certificate is 80% expired. Renewal attempts continue until renewal is successful. Renewal generates a new certificate, which results in a new public/private key pair.
277+
278+
> [!NOTE]
279+
> Renewal behavior on iOS/iPadOS and macOS: Certificates can only be renewed during the renewal threshold phase. In addition, the device has to be unlocked while synching with Intune. If the renewal was not successful, the expired certificate will remain on the device and Intune does not trigger a renewal anymore. Also, Intune does not offer an option to redeploy expired certificates. Affected devices need to be excluded from the SCEP profile temporarily to remove the expired certificate and request a new one.
277280
278281
- **SCEP Server URLs**:
279282

0 commit comments

Comments
 (0)