Security

 View Only
last person joined: 5 days ago 

Enterprise security using ClearPass Policy Management, ClearPass Security Exchange, IntroSpect, VIA, 360 Security Exchange, Extensions and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Microsoft Intune SCEP Extension

This thread has been viewed 31 times
  • 1.  Microsoft Intune SCEP Extension

    Posted Jan 17, 2023 04:44 AM
    We are planning to roll out device certificates through the Intune SCEP Extension for Onboard Enrollment according to this technote: https://www.arubanetworks.com/techdocs/ClearPass/TechNotes/Extensions-Intune-Onboard/Default.htm
    Unfortunately, the Intune SCEP extension relies on the deprecated Azure Active Directory Graph API, which will be shut down after June 30, 2023. Are there any plans to migrate the extension to the Microsoft Graph API soon? Or would it be wise to go for another workflow?

    ------------------------------
    Thanks
    Daniel
    ------------------------------


  • 2.  RE: Microsoft Intune SCEP Extension

    Posted Jan 17, 2023 11:49 PM
    You can use PacketFence's Intune SCEP integration by itself, I helped patch it for the MS Graph API a few months ago. PacketFence is a whole RADIUS server but you don't need to touch the RADIUS bits to use its CA. Also AGPL is a lot cheaper than Onboard licensing ...


  • 3.  RE: Microsoft Intune SCEP Extension

    EMPLOYEE
    Posted Jan 18, 2023 03:32 PM
    The official support of Intune SCEP is coming 'shortly'.


  • 4.  RE: Microsoft Intune SCEP Extension
    Best Answer

    EMPLOYEE
    Posted Jan 18, 2023 04:34 PM
    The current extension ID now points to a 1.1.0 version that removes the deprecated API.  You no longer need the AD Graph permission.  Docs and a formal public release coming soon.


  • 5.  RE: Microsoft Intune SCEP Extension

    Posted Jan 19, 2023 10:29 AM
    Garth,

    thanks for your reply. Didn't expect such a quick response, really appreciate that. At first glance, version 1.1.0 works fine for us!

    ------------------------------
    Thanks
    Daniel
    ------------------------------



  • 6.  RE: Microsoft Intune SCEP Extension

    EMPLOYEE
    Posted Jan 19, 2023 11:32 AM
    Great to hear.  Feel free to tag me with any feedback.  Do you use it in conjunction with the Intune inventory extension for policy?


  • 7.  RE: Microsoft Intune SCEP Extension

    Posted 4 hours ago

    I like to share some experiences we made so far with the current extension. At this point, we do not use the inventory extension yet but we plan to.

    We noticed that at least for iOS devices Intune will request two certificates which will lead to two times more licenses (OnBoard) beeing used. But it seems that this is a known/expected behaviour of Intune and we have to deal with this via Script/API.

    We also noticed, that the extension shuts down unexpectedly sometimes without any errors logged. We have to further investigate on that.

    Looking forward to the formal public release of this!



    ------------------------------
    Thanks
    Daniel
    ------------------------------