mscep_admin access is forbidden to service account

Simon Matthews 0 Reputation points
2023-05-18T05:14:17.4366667+00:00

I have an NDES server configured for use with Certificate Connector for Microsoft Intune. I am attempting to use this NDES server with Jamf as well. The problem I am having is the inability to access the mscep_admin page. I have attempted to use the service account used when creating this but I receive a forbidden access message.

I have tried reinstalling and everything I can find. Does anyone have any idea why this page would be completely inaccessible to any account?

Microsoft Security | Intune | Configuration
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Crystal-MSFT 53,991 Reputation points Microsoft External Staff
    2023-05-18T06:18:34.6366667+00:00

    @Simon Matthews, Thanks for posting in Q&A. Based as I know, when we open a web browser and browse the SCEP server URL like https://contoso.com/certsrv/mscep/mscep.dll, the result should be: HTTP Error 403.0 – Forbidden. This result indicates the URL is functioning correctly. From your description, it seems we get the Forbidden message as well. This is by design and means it is working.

    Here is a link with more details for your reference:

    https://learn.microsoft.com/en-us/troubleshoot/mem/intune/certificates/troubleshoot-scep-certificate-device-to-ndes#test-and-troubleshoot-the-scep-server-url

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Simon Matthews 0 Reputation points
    2023-05-18T23:01:18.4866667+00:00

    If you use Certificate Connector for Microsoft Intune, the mscep_admin page is not available. You would have to have a separate server with NDES installed as normal to access this.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.