Azure AD Application Proxy and NDES/SCEP with Intune

sds04563 221 Reputation points
2021-09-29T07:13:44.207+00:00

Hello Team,

following this Microsoft Learn guide

https://learn.microsoft.com/en-us/azure/active-directory/app-proxy/active-directory-app-proxy-protect-ndes

to configure an Azure AD Application Proxy (to support an internal NDES and Intune Certificate Connector) will leave you with an IIS default page which is accessible from the internet. The certsrv/mscep/mscep.dll shows 403-Forbidden Message. Both is expected.

But what can I do to harden IIS? Are there any best practices? My first thought was just to publish the url with certsrv/mscep/mscep.dll and not just https://server.domain.tld

You can only use "Passthrough" in Azure AD App Proxy as it is the only way SCEP will work.

Thank you

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. WalBenk 0 Reputation points
    2023-01-30T11:15:40.4933333+00:00

    Hi all,

    I'm preparing a Poc for CA implementation and want to know the best practice of installing "Azure AD Application Proxy Agent". It should be on a separate server/VM (1) or could be installed on NDES server (2)? pro/cons ?

    Thanks in Advance

    WalBenK

    User's image


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.