Onboard macOS devices with certificates using Jamf School and SCEP
In this topic, you will learn how to deploy Portnox™ Cloud certificates via Jamf School and SCEP to manage macOS devices.
This guide covers only network authentication. It assumes that you already manage your devices in Jamf School. If you plan to use user certificates, make sure that all devices enrolled in Jamf School have an assigned owner whose email address is the same as in the Portnox Cloud authentication repository used for the group. Also decide how to deploy the profile to your devices, for example, scope the profile to a device group so that Jamf School installs the profile automatically on each device in the group at the next device check-in.
Observed potential issues:
-
If Portnox Cloud shows email as the user in the certificate instead of the user’s email address, and authentication fails, check that the device has an owner in Jamf School, in the same location as the device. Without an owner, Jamf School sends variables such as %Email% as literal text.
-
Jamf School doesn’t renew SCEP certificates automatically, and Portnox Cloud doesn’t track their validity. When a certificate expires, the device loses network access. macOS devices can display a warning before the certificate expires, so users can remind you, but iOS devices don’t display any warnings. You need to manually track expiration dates and renew certificates before they expire.
To renew a certificate, reinstall the profile on the device page, or edit and save the profile to send it again to all devices in scope.
Turn on the Portnox Cloud SCEP services
In this section, you will configure Portnox™ Cloud to provide SCEP services to your devices.
If you have previously turned on the Portnox Cloud SCEP services, skip to the later step in which you get the Cloud SCEP URL and password.
Portnox Cloud SCEP services let devices contact the Cloud SCEP server and get a unique certificate for the device or for the specific user of the device.
Download the root CA certificate
In this section, you will download the root CA certificate from Portnox™ Cloud, which is needed to create a profile.
Result: The root CA certificate file is in the Downloads folder on the local disk.
Optional: Hand over information from the Portnox Cloud team to the Jamf School team
In this section, you will learn what information was collected in previous steps from Portnox Cloud, which is needed to configure Jamf School to work with Portnox Cloud.
If different people are responsible for managing Portnox Cloud and Jamf School, here is the information you need to hand over:
-
The URL of the Portnox Cloud SCEP server. For example, https://scep.portnox.com/b2973887-1274-45d4-91d0-4a342a861c76.
-
The password for the SCEP server.
-
The root CA certificate file in the X.509 format. For example, rootCertificate.crt.
Create a Jamf School profile
In this section, you will create a profile in Jamf School that lets managed devices get certificates from the Portnox™ Cloud SCEP server.
Configure the profile for Wi-Fi
In this section, you will edit the profile and add a Wi-Fi network configuration. This will let your managed devices access the Wi-Fi network configured in Portnox™ Cloud by using certificates obtained from the Portnox SCEP server.
Configure the profile for Ethernet
In this section, you will edit the profile and add an Ethernet network configuration. This will let your managed macOS devices access the Ethernet network configured in Portnox™ Cloud by using certificates obtained from the Portnox SCEP server.

































