Avatar of Sal Qamar
Sal Qamar
Flag for United Kingdom of Great Britain and Northern Ireland asked on

INtune

I need to get some help on an issue that is affecting our Apple devices, iphones, ipads and macbooks.

To connect to our corporate WiFi, we authenticate using device certificates. The certificate path comes from out RootCA > IntermediateCA > Device certificate and we deploy all certificates via Intune.

Our windows devices using device certs can connect no problem at all. Any apple device that has never been enrolled onto Intune before will not receive the device certificate. The Root and Intermediate certs are deployed but the device cert fails, thus none of our macbooks, ipads and iphones can connect to our corporate WiFi.

I have checked all certificates to ensure they haven’t expired. I have recreated the Root, Inter and device certificate policy and applied them to a test group and the same thing happens.

The below is showing my test macbook. The root cert and intermediate certs have applied but the ‘Certificate Device – macOS’ has an error




The same also for my ‘TEST-‘ root, inter and device certs. All apply apart from the device cert

Clicking on the error message shows the below:




Im not sure what the issue is as it has worked in the past with no issue for all OS types. We haven’t made any changes so not sure if this relates to an Apple update, or Microsoft changing something in the background for SCEP device certificate deployment



iOS* Microsoft InTune Company Portal* Mac OS* Mobile Device Management (MDM)

Avatar of undefined
Last Comment
Jackie Man

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
Jackie Man

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy