What is the benefit of using SCEP with Intune.

brichardi 361 Reputation points
2023-01-19T16:35:19.44+00:00

Hello Intune Guru.

I have a question about secure intune. I have seen some organizations using SCEP in combination with Intune MDM. What is the benefit of using SCEP withe Intune?

Also, my organization thinking about creating Intune Autopilot to enroll Windows 11. Since 95% of our security settings in on GPOs, and Intune policies is not the same as GPO. How can we apply the same security settings from GPO to Intune MDM Autopilot devices.

Thanks for your help.

Microsoft Security | Intune | Security
Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Compliance
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Jordi Rojas 271 Reputation points
    2023-01-19T16:43:26.2733333+00:00

    SCEP (Simple Certificate Enrollment Protocol) is a protocol that allows devices to securely enroll for and retrieve digital certificates. When used with Microsoft Intune, SCEP can provide the following benefits:

    • Securely provision and manage device certificates for Wi-Fi, VPN, email, and other services
    • Easily revoke and replace lost or compromised certificates
    • Automate the enrollment process for devices, reducing the need for manual intervention
    • Provide a secure way for devices to authenticate to corporate resources

    Overall, SCEP allows for secure and automated management of digital certificates on devices, which can help improve the security of the device and the organization's network.

    1 person found this answer helpful.
    0 comments No comments

  2. Crystal-MSFT 53,981 Reputation points Microsoft External Staff
    2023-01-20T02:44:50.76+00:00

    @brichardi, Thanks for posting in Q&A.

    Intune supports use of the Simple Certificate Enrollment Protocol (SCEP) to authenticate connections to your apps and corporate resources. When your infrastructure supports SCEP, you can use Intune SCEP certificate profiles (a type of device profile in Intune) to deploy the certificates to your devices.

    https://learn.microsoft.com/en-us/mem/intune/protect/certificates-scep-configure

    To find if the setting in GPO exists on Intune, you can try the feature "Group Policy analytics". You can see more details in the following link:

    https://learn.microsoft.com/en-us/mem/intune/configuration/group-policy-analytics

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.