Configure Okta as a CA with delegated SCEP challenge for macOS using MEM (formally Intune)
Configure a certificate authority (CA) to issue client certificates to your targeted macOS devices. This procedure describes how to create a Simple Certificate Enrollment Protocol (SCEP) profile in Microsoft Endpoint Manager (MEM) and generate a SCEP URL in Okta.
Prerequisites
- Certificates deployed for digital signature, but not for other purposes (for example, encryption)
- Okta Admin Console
- Microsoft Endpoint Manager (MEM)
- Microsoft Azure
Microsoft Endpoint Manager (MEM) is a solution platform that unifies several services. It includes Microsoft Intune for cloud-based device management, Configuration Manager for on premises device management, Co-management, Desktop Analytics, Windows Autopilot, Azure Active Directory, Windows Autopilot, and Endpoint Manager admin center. You can use this procedure if you are using any of these services. For example, you can use this procedure if you are using Microsoft Intune.
Okta as a CA doesn't support renewal requests. Instead, redistribute the profile before the certificate expires to replace the expired certificate. All MDM SCEP policies should be configured to allow for profile redistribution.
Start this Procedure
- Task 1: Register the AAD app credentials for Okta in Microsoft Azure
- Task 2: Configure management attestation and generate a SCEP URL in Okta
- Task 3: Download the x509 certificate from Okta
- Task 4: Create a Trusted Certificate profile in MEM
- Task 5: Create a SCEP profile in MEM
- Task 6: Verify that the SCEP certificate was installed on your macOS devices
Task 1: Register the AAD app credentials for Okta in Microsoft Azure
- In Microsoft Azure, click App registrations.
- Click + New registration.
- On the Register an application page, enter the following:
- Name: Enter a meaningful name for the application.
- Supported account types: Select the appropriate supported account type. Okta tested with Accounts in this organizational directory only ([Your_Tenant_Name] only - Single tenant) selected.
- Redirect URI (optional): Leave blank, or select Web, and then enter a redirect URI.
- Click Register.
- On the app page under Essentials, copy and make a note of the Application (client) ID.
- Add a client secret:
- In the left pane, click Certificates & secrets.
- Under Client secrets, click + New client secret.
- In the Add a client secret section, enter the following:
- Description: Optional. Enter a description for the client secret.
- Expires: Select an expiration time period.
- Click Add.
- In the Client secrets section, copy and make a note of the Value.
The secret appears under Client secrets.
- Set the Intune scep_challenge_provider permissions:
- In the left pane, click API permissions.
- Click + Add a permission.
- In the Request API permissions section, scroll down, and then click Intune.
- Under What type of permissions does your application require?, click Application permissions.
- In the Select permissions search field, enter scep, and then select the scep_challenge_provider checkbox.
- Click Add permissions.
- In the Configured permissions section, click P Grant admin consent for [Your_Tenant_Name].
- Click Yes in the message that appears.
-
Set the Microsoft Graph Application.Read.All permissions:
- Click + Add a permission.
- In the Request API permissions section, click Microsoft Graph.
- Under What type of permissions does your application require? click Application permissions.
- In the Select permissions search field, enter application, expand Application, and then select the Application.Read.All checkbox.
- Click Add permissions.
- In the Configured permissions section, click PGrant admin consent for [Your_Tenant_Name].
- Click Yes in the message that appears.
You will paste this value in the Okta Admin Console in Task 2.
Task 2: Configure management attestation and generate a SCEP URL in Okta
- In the OktaAdmin Console, go to Security > Device integrations.
- Click the Endpoint management tab.
- Click Add platform.
- Select Desktop (Windows and macOS only).
- Click Next.
- Configure the following:
- Certificate authority: Select Use Okta as certificate authority.
- SCEP URL challenge type: Select Dynamic SCEP URL, and then select Microsoft Intune (delegated SCEP).
- Enter the values that you copied from Microsoft Azure into the following fields:
- AAD client ID: Enter the value you copied from Task 1.
- AAD tenant: Enter your AAD tenant name followed by .onMicrosoft.com.
- AAD secret: Enter the secret Value you copied from Task 1.
For example:
- Click Generate.
- Copy and save the Okta SCEP URL. You will paste the URL in Microsoft Endpoint Manager in Task 5.
Task 3: Download the x509 certificate from Okta
- In the Okta Admin Console, go to Security > Device integrations.
- Click the Certificate authority tab.
- In the Actions column for Okta CA, click the Download x509 certificate icon.
- Rename the downloaded file, so that it includes a .cer extension.
You will upload the certificate (CER file) to Microsoft Endpoint Manager (MEM) in Task 4.
Task 4: Create a Trusted Certificate profile in MEM
- In the Microsoft Endpoint Manager (MEM) admin center, go to Devices.
- Click Configuration profiles.
- Click + Create profile.
- In Create a profile, do the following:
- On the Trusted certificate page Basics tab, do the following:
- On the Trusted certificate page Configuration settings tab, do the following:
- Certificate file: Select the x509 certificate (CER file) that you downloaded from Okta in Task 3.
- Destination store: Select Computer certificate store - Intermediate.
- Click Next.
- On the Trusted certificate page Assignments tab, do the following:
- Included groups: Assign the trusted certificate profile to one or more user groups. The user group(s) must be the same as the group(s) you will assign the SCEP profile to in Task 5.
- Click Next.
Make sure the user group(s) specified in both profiles are the same.
- On the Trusted certificate page Applicability rules tab, do the following:
- Configure any required rules.
- Click Next.
- On the Trusted certificate page Review + create tab, review the configuration, and then click Create.
Task 5: Create a SCEP profile in MEM
- In the Microsoft Endpoint Manager (MEM), go to Devices.
- Click Configuration profiles.
- Click + Create profile.
- In Create a profile, enter the following:
- On the SCEP certificate page Basics tab, do the following:
- Name: Enter a name for the certificate.
- Description: Optional. Enter a description for the certificate.
-
Click Next.
- On the SCEP certificate page Configuration settings tab, do the following:
-
Certificate type: Select User.
-
Subject name format: Enter a subject name. For example, CN={{UserPrincipalName}} managementAttestation {{DeviceId}}.
-
Certificate validity period: Select Years in the list, and then enter 1 in the next field.
-
Key usage: Select Digital signature.
-
Key size (bits): Select 2048.
-
Click + Root Certificate.
-
On the Root Certificate page, select the trusted certificate that you created earlier in Task 4.
- Click OK.
-
Under Extended key usage, set Predefined values to Client Authentication.
-
SCEP Server URLs: Enter the SCEP URL you generated in Task 2.
-
Allow all apps access to private key: Select Enable.
-
Click Next.
- On the SCEP certificate page Assignments tab, do the following:
- Assign the SCEP certificate to the same user group(s) to which you assigned the Trusted certificate profile in Task 4.
- Click Next.
Make sure the user group(s) specified in both profiles are the same.
- On the SCEP certificate page Review + create tab, review the configuration, and then click Create.
Okta does not require the subject name to be in any particular format. Choose a name that indicates that the certificate is used as the device management signal to Okta. As a best practice, you can also include profile variables provided by MEM to include the device ID (UDID) and user identifier. For a list of supported variables, see MEM document Use SCEP certificate profiles with Microsoft Intune.
Task 6: Verify that the SCEP certificate was installed on your macOS devices
- On a macOS device managed by MEM, open Keychain > Login.
- Verify that a client certificate and associated private key exists.
- Make sure the private key is accessible to all applications: