Today, we will discuss Intune SCEP with Joy – Learn how to use unique certificate templates to deploy different SCEP certificates within the same environment.
There may be a scenario where you must use different templates to deploy different SCEP certificates to your Intune-managed endpoints.
For example, you may require that the SCEP certificate be deployed to group A to use template A and group B to use template B. A unique SCEP certificate will be deployed for the different profiles—email, VPN, and Wi-Fi.”
The above has always been a supported scenario and is in use in many enterprise environments.
- Create SCEP Certificate Profiles in Intune Deploy SCEP Profiles to Windows 10 Devices
- Create SCEP Certificate Profiles Deploy SCEP Profiles to iOS Devices using Intune.
- Part 1 – Learn The Basic Concepts of PKI
- Part 2 – Knowing SCEP – The General Workflow
- Part 3 – Intune SCEP PKI Implementation Deep Dive
- Part 4 – Intune SCEP Certificate Workflow Analysis
| Index |
|---|
| Understanding the Logic – Intune SCEP with Joy |
| Proof Of Concept |
Understanding the Logic – Intune SCEP with Joy
The Extended Key Usage (EKU) parameter determines that the primary use case of an SCEP certificate is to serve client authentication.
The SCEP certificate template configured in CA must add Client Auth to its EKU.

You define the same while configuring the SCEP certificate profile from Intune.

Note: Selecting EKU as Any Purpose suffices for the obtained certificate to be used for auth purposes, as long as the certificate template used for creating the certificate has Client Authentication selected in its EKU.
However, the template that NDES (SCEP service) will use to make the on-behalf certificate request to the CA is determined based on the value of the Key Usage parameter of the Certificate Signing Request (CSR) that the device sends to the SCEP service, upon receiving the instructions from Intune as part of the SCEP payload.

When the SCEP service receives the certificate request from a device, it inspects the CSR to get the value for the Key Usage parameter and, based on it, determines the template to be used for making the certificate request to CA on-behalf, as defined in the reg_keys under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MSCEP.

While configuring the SCEP certificate profile in Intune, based on the selection of Key Usage
- Digital signature (=
SignatureTemplatein MSCEP reg) - Key encipherment (=
EncryptionTemplatein MSCEP reg) - Digital signature and
