Skip to content

Commit ecc6495

Browse files
authored
Update certificates-profile-scep.md
Made a number of changes to the doc page related to AOSP, and a recent discovery that SHA-1 hash algorithm option is ignored on AE, and AOSP - SHA-2 is used instead.
1 parent 7f188b8 commit ecc6495

1 file changed

Lines changed: 29 additions & 7 deletions

File tree

memdocs/intune/protect/certificates-profile-scep.md

Lines changed: 29 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -57,11 +57,30 @@ Devices that run Android Enterprise might require a PIN before SCEP can provisio
5757

5858
SCEP certificate profiles for the *Fully Managed, Dedicated, and Corporate-Owned Work Profile* profile have the following limitations:
5959

60-
1. Under Monitoring, certificate reporting isn't available for Device Owner SCEP certificate profiles.
61-
62-
2. You can't use Intune to revoke certificates that were provisioned by SCEP certificate profiles for Device Owners. You can manage revocation through an external process or directly with the certification authority.
63-
64-
3. For Android Enterprise dedicated devices, SCEP certificate profiles are supported for Wi-Fi network configuration, VPN, and authentication. SCEP certificate profiles on Android Enterprise dedicated devices aren't supported for app authentication.
60+
a. Under Monitoring, certificate reporting isn't available for **Device Owner** SCEP certificate profiles.
61+
62+
b. You can't use Intune to revoke certificates that were provisioned by SCEP certificate profiles for **Device Owner**. You can manage revocation through an external process or directly with the certification authority.
63+
64+
c. For Android Enterprise dedicated devices, SCEP certificate profiles are supported for Wi-Fi network configuration, VPN, and authentication. SCEP certificate profiles on Android Enterprise dedicated devices aren't supported for app authentication.
65+
66+
For **Android (AOSP)**, the following limitations apply:
67+
a. Under Monitoring, certificate reporting isn't available for **Device Owner** SCEP certificate profiles.
68+
b. You can't use Intune to revoke certificates that were provisioned by SCEP certificate profiles for **Device Owners**. You can manage revocation through an
69+
external process or directly with the certification authority.
70+
c. SCEP certificate profiles are supported for Wi-Fi network configuration. VPN configuration profile support is not available. A future update may include
71+
support for VPN configuration profiles.
72+
d. The following 3 variables are not available for use on Android (AOSP) SCEP certificate profiles. Support for these variables will come in a future update.
73+
· onPremisesSamAccountName
74+
· OnPrem_Distinguished_Name
75+
· Department
76+
77+
NOTE: **Device Owner** is equivalent to Corporate Owned devices. The following are considered as Device Owner:
78+
• Android Enterprise - Fully Managed, Dedicated, and Corporate-Owned Work Profile
79+
• Android AOSP
80+
o User-affinity
81+
o User-less
82+
83+
![image](https://user-images.githubusercontent.com/49950578/191582773-3066ebcd-374c-4353-bdfe-6013122c5369.png)
6584

6685
4. Select **Create**.
6786

@@ -75,7 +94,7 @@ Devices that run Android Enterprise might require a PIN before SCEP can provisio
7594

7695
- **Certificate type**:
7796

78-
*(Applies to: Android, Android Enterprise, iOS/iPadOS, macOS, Windows 8.1, and Windows 10/11)*
97+
*(Applies to: Android, Android Enterprise, Android (AOSP), iOS/iPadOS, macOS, Windows 8.1, and Windows 10/11)*
7998

8099
Select a type depending on how you'll use the certificate profile:
81100

@@ -259,9 +278,12 @@ Devices that run Android Enterprise might require a PIN before SCEP can provisio
259278

260279
- **Hash algorithm**:
261280

262-
*(Applies to Android, Android enterprise, Windows 8.1, and Windows 10/11)*
281+
*(Applies to Android, Android (AOSP), Android enterprise, Windows 8.1, and Windows 10/11)*
263282

264283
Select one of the available hash algorithm types to use with this certificate. Select the strongest level of security that the connecting devices support.
284+
285+
NOTE: Android AOSP and Android Enterprise devices will select the strongest algorithm supported - SHA-1 will be ignored, and SHA-2 will be used instead.
286+
265287

266288
- **Root Certificate**:
267289

0 commit comments

Comments
 (0)