@testuser7 , Based on my understanding, when the profile is pushed down to the device, it will process certificate enrollment when the Windows Hello for Business is set. Device processes SCEP profile containing URL for NDES server, and generate private/public key pair. Device contacts NDES URL, validates then send CSR and challenge. NDES server validate the request and if the challenge is correct, it then contact CA to help to request certificate.
Based on my test, if the windows hello for business is not configured when we receive the policy, the profile will be failed to deploy with error.
Hope it can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.