Share via

CMG: Moving to token based auth from HTTPS

Bryan Powell 41 Reputation points
2021-03-26T13:30:25.027+00:00

Last summer like many organizations we deployed a CMG to allow work from home to be more seamless in terms of MECM management using client based certificates and HTTPS MPs. Since then we have upgraded to the point where the token based authentication is an option. Because it is inherently more simple than a full HTTTPS/client certificate setup, I am wondering what the process would be for migrating to token based auth.

If I am understanding what I am reading this process is fairly hands off and up to date clients will have already gotten the token essentially ready for use. This leads me to believe I can just flip the switch to http/https both being allowed and that is it. This seems dangerously simple though, so I wanted to check here to see if I am missing anything obvious. The docs do seem to indicate token based auth may be more for the purposes of provisioning non-typical clients, so perhaps I am off base.

Microsoft Security | Intune | Configuration Manager | Other
0 comments No comments

Answer accepted by question author

  1. Jason Sandys 31,421 Reputation points Microsoft Employee Moderator
    2021-03-29T03:32:43.093+00:00

    I can't say I've tested this scenario explicitly, but this is all that it should take. I would remove the PKI-issued client auth certs from the clients as well to prevent any client selection conflict.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Bryan Powell 41 Reputation points
    2021-03-29T12:19:13.42+00:00

    Thanks. We will do some testing if we attempt this change, and if I have anything of note to report I will share it here.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.