Configuration for CBE
Follow this guide to set up Certificate Deployment with Intune.
Root Certificate
Download and save your CA Certificate (.cer).
Go to Intune > Devices > Windows > Configuration profiles.
Create a profile for Windows 8.1 and later with type Trusted certificate in Microsoft Intune
Upload your previously downloaded .cer file.
Please choose All Users and/or All Devices or a dedicated group for assignment.
User Client Certificates
Create a profile for Windows 8.1 and later with type SCEP certificate in Microsoft Intune
Certificate type: User
Subject Name format : CN = {{UserName}}, E={{EmailAddress}}
Subject alternative name : User principal name (UPN), '{{UserPrincipalName}}'
Certificate Validity Period : 1 year
KSP : Enroll to Trusted Platform Module (TPM) KSP, otherwise fail
Key usage : Digital signature and Key encipherment
Key size : 2048
Hash algorithm : SHA-2
Root certificate : Profile created from before
Extended key use : Client Authentication.
You're all setup!🥳
You can check the certificate deployment by logging into your device and checking the Certificate Manager.