Share via

NDES machine certificate (Intune SCEP profile) not auto renewing (sometimes?)

Sebastian Cerazy 351 Reputation points
2023-01-10T12:35:28.657+00:00

My machine certificates issued from internal CA via NDES/SCEP profile in Intune do not always renew Recently had a bunch of users that needed manual sync forced on their AAD joined/Intune managed machines with cable connection to obtain the new certificate The machines were previously ON, so would expect that they should auto renewed within the 6 weeks period as specified in the template used

Any ideas?

Thanks

Seb

Microsoft Security | Intune | Other
0 comments No comments

2 answers

Sort by: Most helpful
  1. Sebastian Cerazy 351 Reputation points
    2023-01-12T09:12:55.67+00:00

    Correct, auto renew did not happen on some devices for a reason that I could not figure

    I can use uncle G probably as well as you, so already been through this link

    Was this answer helpful?


  2. Crystal-MSFT 54,311 Reputation points Microsoft External Staff
    2023-01-11T06:12:34.4966667+00:00

    @SebastianCerazy-1155, Thanks for posting in Q&A. From your description, it seems the SCEP certificate renew is not working on some devices. To troubleshoot this, you can refer to the following link to see if there's any finding.

    https://oliverkieselbach.com/2022/09/21/deep-dive-of-scep-certificate-request-renewal-on-intune-managed-windows-clients/

    Note: Non-Microsoft link, just for the reference.

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.