Once you have certificate deployment working, you can use it for several purposes. One example would be to use certificate based authentication against Exchange (on-prem), VPN or WiFi Profiles. Certificate based authentication against WiFi profiles is a common ask, in this post I'll explain how to configure this in ConfigMgr 2012 R2.
After deploying the profile, wait a few minutes and enroll a new user or enforce a policy refresh on Windows Phone 8.1. You phone should connect to the WiFi automatically using the SCEP Certificate.
If this post helped you, consider leaving a reply.
Are you trying to configure certificate deployment for mobile devices and run into the error 12186 in ndesplugin.log? This post might help you reach a solution.
The exact error shown in ndesplugin.log is:
Failed to send http request /CMCertificateRegistration/Certificate/VerifyRequest. Error 12186
This error occurs if the account under which NDES application pool runs may not have read permission to the client certificate's private key while doing https connection to the Certificate Registration Point (CRP).
Restart the NDES server and you should not get the same error. Please consider leaving a reply in case this post helped you.
There are several ways to initiate a revocation of a certificate on a mobile device, in this post we will discuss the options and their behavior per platform. It’s important to note that we can only revoke certificates which are delivered via SCEP.
There are two types of removal:
From a server side perspective, the certificate will always be revoked on the CA. From a client side perspective, the certificate will be removed from the device. This applies to all platforms we currently support: Windows, Windows Phone, Android and iOS with one exception (see below).
The only scenario is we are currently investigating is removal type 2 in combination with Windows Phone, in certain conditions the certificate is not removed from the device.
My role has previously primarily focused on Microsoft Intune, nowadays it’s more towards our whole Enterprise Mobility Suite. This includes Azure AD premium, Microsoft Intune and Azure Rights Management Service. Due to the change of focus (and name change of Microsoft Intune) I decided to create a new blog. My previous blogs and content can be found here:
Technical tips related to, mostly, Intune: