Authorize CZERTAINLY
To allow a third-party SCEP server to run custom challenge validation with Intune, create an app in Azure AD. This app gives delegated rights to Intune to validate SCEP requests.
Follow Microsoft guide to Authorize communication between CA and Intune and
- Create an application in Azure Active Directory
- Create an application client secret
- Manage application API permissions
Credentials
After this step, you should have new registered application with required permissions. Ensure that you have the following information recorded to Configure Intune SCEP Profile:
- Application (client) ID
- Directory (tenant) ID
- Application client secret value