Onboard Windows devices with certificates using Microsoft Intune and SCEP
In this topic, you will learn how to deploy Portnox™ Cloud certificates to Windows devices via Microsoft Intune SCEP.
Turn on the Portnox Cloud SCEP services
In this section, you will configure Portnox™ Cloud to provide SCEP services to your devices.
If you have previously turned on the Portnox Cloud SCEP services, skip to the step in which you get the Cloud SCEP URL for Microsoft Intune.
Portnox Cloud SCEP services let devices contact the Cloud SCEP server and get a unique certificate for the device or for the specific user of the device.
-
In the Cloud portal top menu, click on the Settings option.
-
In the right-hand side pane, find and click on the CLEAR GENERAL SETTINGS heading.
More options appear under the CLEAR GENERAL SETTINGS heading and description.
-
Enable integration with SCEP services.
-
Click on the ⧉ icon next to the SCEP URL for MS
Intune field to copy the SCEP URL, and paste it in a text file for later use.
Download the root CA certificate from Portnox Cloud
In this section, you will download the Portnox™ Cloud root CA certificate from the Cloud portal.
You need the root CA certificate so that your managed devices can verify the validity of cloud RADIUS servers, which have certificates signed by this root CA certificate. If the root CA certificate is not distributed to managed devices, some devices may show a security warning each time that the user connects to networks managed by Portnox Cloud.
-
In the Cloud portal top menu, click on the Settings option.
-
In the right-hand side pane, find and click on the CLEAR RADIUS SERVICE heading.
The active servers appear under the CLEAR RADIUS SERVICE heading and description along with advanced options.
- Click on any of the active RADIUS services to show its configuration.
-
Click on the Download root certificate link to download the root CA certificate.
Save the file on your disk to use it later. The default name of the file is rootCertificate.cer.
Download the tenant CA certificate from Portnox Cloud
In this section, you will download the Portnox™ Cloud tenant CA certificate from the Cloud portal and convert it to the Base-64 encoded X.509 format.
You need the tenant CA certificate from Portnox Cloud so that your managed devices can verify the validity of individual SCEP certificates, which are signed using the tenant CA certificate.
-
In the Cloud portal top menu, click on the Settings option.
-
In the right-hand side pane, find and click on the CLEAR GENERAL SETTINGS heading.
More options appear under the CLEAR GENERAL SETTINGS heading and description.
-
Scroll down to the TRUSTED ROOT CERTIFICATES section and click on the
Download link, then save the downloaded file.
The default name of the file is Your_tenant_name - Portnox CLEAR.pfx, for example, Portnox - Portnox CLEAR.pfx.
-
In Windows, right-click on the downloaded file and select Open from the context menu.
The file will be opened in the Windows certificate manager.
-
In the certificate manager window, open the Certificates section in the left-hand pane and
then double-click on Portnox - Portnox CLEAR in the right-hand side pane.
-
In the Certificate window, click on the Details tab and then click on
the Copy to File button.
-
In the Certificate Export Wizard, export the certificate in base-64 encoded format.
Create a profile for the root CA certificate
In this section, you will create a profile in Microsoft Intune for the downloaded Portnox™ Cloud root CA certificate.
- Open the Microsoft Intune portal in your browser: intune.microsoft.com.
-
In the Devices | Configuration pane, in the Policies tab, click on the
Create button and select the New Policy option.
-
In the Create a profile pane:
- In the Platform field, select Windows 10 and later.
- In the Profile type field, select Templates
- In the search bar, type trusted.
- In the Template name field, click on the Trusted certificate option.
- Click on the Create button.
-
In the Basics step of the Trusted certificate wizard, in the
Name field, type a name for this profile, optionally fill in the
Description field, and click on the Next button.
In this example, we used the name Portnox Cloud root CA, but you can use any name you like.
-
In the Configuration settings step of the wizard, click on the 🗀 icon to open the downloaded root CA file, leave the default value of the
Destination store field, and click on the Next button.
In this example, the file has the default name rootCertificate.cer.
-
In the Assignments step of the wizard, use relevant options to assign this profile to
specific groups or all users/devices, and then click on the Next button.
- In the Applicability Rules step of the wizard, add rules to apply this configuration profile depending on the operating system version/edition, if necessary, and then click on the Next button.
- In the Review + create step of the wizard, review all the information, and then click on the Create button.
Result: You created a trusted certificate profile for the Portnox Cloud root CA certificate.
Create a profile for the tenant CA certificate
In this section, you will create a profile in Microsoft Intune for the downloaded Portnox™ Cloud tenant CA certificate.
- Open the Microsoft Intune portal in your browser: intune.microsoft.com.
-
In the left-hand menu, select the Devices option.
-
In the left-hand menu of the Devices pane, select the Configuration
option.
-
In the Devices | Configuration pane, in the Policies tab, click on the
Create button and select the New Policy option.
-
In the Create a profile pane:
- In the Platform field, select Windows 10 and later.
- In the Profile type field, select Templates
- In the search bar, type trusted.
- In the Template name field, click on the Trusted certificate option.
- Click on the Create button.
-
In the Basics step of the Trusted certificate wizard, in the
Name field, type a name for this profile, optionally fill in the
Description field, and click on the Next button.
In this example, we used the name Portnox Cloud tenant CA, but you can use any name you like.
-
In the Configuration settings step of the Trusted certificates wizard,
click on the 🗀 icon to open the downloaded tenant CA file, leave the
default value of the Destination store field, and click on the Next
button.
In this example, the file has the name tenantCertificate.cer.
-
In the Assignments step of the wizard, use relevant options to assign this profile to
specific groups or all users/devices, and then click on the Next button.
- In the Applicability Rules step of the wizard, add rules to apply this configuration profile depending on the operating system version/edition, if necessary, and then click on the Next button.
- In the Review + create step of the wizard, review all the information, and then click on the Create button.
Result: You created a trusted certificate profile for the Portnox Cloud tenant CA certificate.
Create a profile for SCEP device certificates
In this section, you will create a profile in Microsoft Intune for unique device certificates, which are generated by Portnox™ Cloud for the devices, and obtained through SCEP requests.
You need to complete this task only if you want to use device certificates for some or all of your devices. If you want to use only user certificates, complete the next task instead. Device certificates are useful for devices such as kiosks.
- Open the Microsoft Intune portal in your browser: intune.microsoft.com.
-
In the left-hand menu, select the Devices option.
-
In the left-hand menu of the Devices pane, select the Configuration
option.
-
In the Devices | Configuration pane, in the Policies tab, click on the
Create button and select the New Policy option.
-
In the Create a profile pane:
- In the Platform field, select Windows 10 and later.
- In the Profile type field, select Templates
- In the search bar, type scep.
- In the Template name field, click on the SCEP certificate option.
- Click on the Create button.
-
In the Basics step of the SCEP certificate wizard, in the
Name field, type a name for this profile, optionally fill in the
Description field, and click on the Next button.
In this example, we used the name Portnox Cloud SCEP Device, but you can use any name you like.
-
In the Configuration settings step of the SCEP certificates wizard,
fill in the fields as follows, and then click on the Next button.
Adjust the proposed values to your requirements and your environment, if needed.
-
In the Assignments step of the wizard, use relevant options to assign this profile to
specific groups or all users/devices, and then click on the Next button.
- In the Applicability Rules step of the wizard, add rules to apply this configuration profile depending on the operating system version/edition, if necessary, and then click on the Next button.
- In the Review + create step of the wizard, review all the information, and then click on the Create button.
Result: You created a profile for device certificates obtained through SCEP.
Create a profile for SCEP user certificates
In this section, you will create a profile in Microsoft Intune for unique user certificates, which are generated by Portnox™ Cloud for the users of devices, and obtained through SCEP requests.
You need to complete this task only if you want to use user certificates for some or all of your devices. If you want to use only device certificates, complete the previous task only.
- Open the Microsoft Intune portal in your browser: intune.microsoft.com.
-
In the left-hand menu, select the Devices option.
-
In the left-hand menu of the Devices pane, select the Configuration
option.
-
In the Create a profile pane:
- In the Platform field, select Windows 10 and later.
- In the Profile type field, select Templates
- In the search bar, type scep.
- In the Template name field, click on the SCEP certificate option.
- Click on the Create button.
-
In the Basics step of the SCEP certificate wizard, in the
Name field, type a name for this profile, optionally fill in the
Description field, and click on the Next button.
In this example, we used the name Portnox Cloud SCEP User, but you can use any name you like.
-
In the Configuration settings step of the SCEP certificates wizard,
fill in the fields as follows, and then click on the Next button.
Adjust the proposed values to your requirements and your environment, if needed.
-
In the Assignments step of the wizard, use relevant options to assign this profile to
specific groups or all users/devices, and then click on the Next button.
- In the Applicability Rules step of the wizard, add rules to apply this configuration profile depending on the operating system version/edition, if necessary, and then click on the Next button.
- In the Review + create step of the wizard, review all the information, and then click on the Create button.
Result: You created a profile for user certificates obtained through SCEP.
Create a profile for a wired network managed by Portnox Cloud
In this section, you will create a profile in Microsoft Intune for the connection of devices to the Ethernet network managed by Portnox™ Cloud.
- Open the Microsoft Intune portal in your browser: intune.microsoft.com.
-
In the left-hand menu, select the Devices option.
-
In the left-hand menu of the Devices pane, select the Configuration
option.
-
In the Devices | Configuration pane, in the Policies tab, click on the
Create button and select the New Policy option.
-
In the Create a profile pane:
- In the Platform field, select Windows 10 and later.
- In the Profile type field, select Templates
- In the search bar, type wired.
- In the Template name field, click on the Wired network option.
- Click on the Create button.
-
In the Basics step of the Wired network wizard, in the
Name field, type a name for this profile, optionally fill in the
Description field, and click on the Next button.
In this example, we used the name Portnox Cloud Ethernet, but you can use any name you like.
-
In the Configuration settings step of the wizard, fill in the following fields, and then
click on the Next button.
Adjust the proposed values to your requirements and your environment, if needed.
-
In the Assignments step of the wizard, use relevant options to assign this profile to
specific groups or all users/devices, and then click on the Next button.
- In the Applicability Rules step of the wizard, add rules to apply this configuration profile depending on the operating system version/edition, if necessary, and then click on the Next button.
- In the Review + create step of the wizard, review all the information, and then click on the Create button.
Result: You created a profile for Windows devices and the Ethernet network managed by Portnox Cloud.
Create a Windows profile for Wi-Fi managed by Portnox Cloud
In this section, you will create a profile in Microsoft Intune for the connection of Windows devices to the Wi-Fi network managed by Portnox™ Cloud.
- Open the Microsoft Intune portal in your browser: intune.microsoft.com.
-
In the left-hand menu, select the Devices option.
-
In the left-hand menu of the Devices pane, select the Configuration
option.
-
In the Devices | Configuration pane, in the Policies tab, click on the
Create button and select the New Policy option.
-
In the Create a profile pane:
- In the Platform field, select Windows 10 and later.
- In the Profile type field, select Templates
- In the search bar, type wi-fi.
- In the Template name field, click on the Wi-Fi option.
- Click on the Create button.
-
In the Basics step of the Wi-Fi wizard, in the
Name field, type a name for this profile, optionally fill in the
Description field, and click on the Next button.
In this example, we used the name Portnox Cloud Wi-Fi, but you can use any name you like.
-
In the Configuration settings step of the wizard, in the Wi-Fi type
field, select the Enterprise option, fill in the following fields, and then click on the
Next button.
Adjust the proposed values to your requirements and your environment, if needed.
-
In the Assignments step of the wizard, use relevant options to assign this profile to
specific groups or all users/devices, and then click on the Next button.
- In the Applicability Rules step of the wizard, add rules to apply this configuration profile depending on the operating system version/edition, if necessary, and then click on the Next button.
- In the Review + create step of the wizard, review all the information, and then click on the Create button.
Result: You created a profile for Windows devices and the Wi-Fi network managed by Portnox Cloud.