Category Filter
 
 

Last updated: August 14, 2026

Simple Certificate Enrollment Protocol(SCEP)

Simple Certificate Enrollment Protocol (SCEP) is a protocol standard used in MDM for automated, scalable certificate management. This page explains how SCEP enables certificate-based authentication for Wi-Fi, VPN, and email services without user intervention, eliminating the manual overhead of distributing certificates across large organizations. It covers supported SCEP CA integrations including Generic SCEP, ACME, DigiCert, Microsoft AD CS (NDES), and EJBCA, along with the full set of configurable SCEP profile settings available in MDM.

Simple Certificate Enrollment Protocol(SCEP) is a protocol standard used for certificate management. SCEP is predominantly used for Certificate-based authentication, whereby access to services such as Wi-Fi, VPN and securing e-mail through encryption is carried out using certificates.

The major advantages of certificate-based authentication are:

  • Zero-user intervention as users are authenticated via certificates.
  • Secure network communication as the data is encrypted and authenticated using certificates.

However, to manually distribute certificates is a cumbersome task for IT administrators in large-scale organizations. SCEP helps network administrators to easily install certificates in devices. SCEP provides a simplified and scalable method for handling certificates in large organizations. The difference between Certificate and SCEP is that SCEP policy is used for distributing client certificates to devices while Certificate policy distributes the CA certificates to devices.

The device directly contacts the SCEP server to generate the certificate, therefore ensure the SCEP server is reachable from the device. It is not necessary for the SCEP server to be reachable to MDM

Configuring SCEP in MDM

  1. You can verify Server details such as enrollment challenge password from https://<your-server>/CertSrv/mscep_admin and http://<Your-Server>/crtsrv/mscep/mscep.dll

Types of SCEP Integrations

Generic SCEP CA Integration

ACME CA Integration

DigiCert Integration

Microsoft AD CS Integration

EJBCA CA Integration

PROFILE SETTINGSDESCRIPTION
SCEP Configuration NameThe user-defined configuration name, which is used to refer this configuration in other configurations such as Wi-Fi, VPN etc.,
SCEP SETTINGS
Server URLThe URL to be specified in the device to obtain certificate. Provide HTTP Server URL, if the SCEP server is within the organization network and not exposed to external networks. The certificate is requested through this URL. 
For NDES, the server URL format: https://<your-server>/CertSrv/mscep/mscep.dll
Certificate Authority NameSpecify the name of the Certificate Authority issuing certificates.
SubjectSpecify the details(%username%, %email%, %domainname%,%devicename%) to map the corresponding details in the device.
Note: CN=%firstname%,OU=Zylker,O=Zylker,DC=Zylker,DC=com
Subject Alternative Name TypeSpecify the alternate details(RFC 822 Name, DNS Name, Uniform Resource Identifier).
Subject Alternative Name Type Value (Can be configured only if Subject Alternative Name Type is configured)Specify the value for alternative name type.
NT Principal NameSpecify the NT Principal Name used in the organization.
Maximum Number of Failed AttemptsNumber of attempts to obtain the certificate from the CA.
Time interval between attemptsTime to wait before subsequent attempts to obtain certificate
Challenge TypeA pre-shared secret key provided by the CA, which adds additional layer of security
Enrollment Challenge PasswordProvide the challenge password to be used.
Key SizeSpecify whether the key is 1024 or 2048 bits
Use as Digital SignatureEnabling ensures the certificate can be used as Digital Signature
Use for Key EnciphermentEnabling ensures the certificate can be used as Key Encipherment

Frequently Asked Questions

1. What's the difference between a Certificate profile and a SCEP profile?

A Certificate profile distributes CA certificates to devices, while a SCEP profile is used for distributing user-specific client certificates to devices.

2. Does the SCEP server need to be reachable from the MDM server?

No. The device contacts the SCEP server directly to generate the certificate, so the SCEP server only needs to be reachable from the device, not from MDM.

3. Which certificate authorities can be integrated with MDM using SCEP?

MDM supports Generic SCEP CA, ACME CA, DigiCert, Microsoft AD CS (NDES), and EJBCA CA integrations.

Jump To