Last updated: August 14, 2026
Certificate
This page explains how to configure the Android Certificate policy in MDM to deploy server CA certificates to managed Android devices. The policy secures and validates network communications such as Wi-Fi and email by establishing device trust with the enterprise CA. It applies to Non-Samsung Android 5.0+ devices enrolled as Fully Managed or Fully Managed with Work Profile, and Samsung devices above 4.2. Administrators can learn how to configure certificate files, handle password-protected certificates, and manage certificate renewals upon expiry.
Certificate policy lets you deploy server CA certificates, to secure and configure features such as, Wi-Fi, E-mail etc., on managed devices. This policy is ideally used to secure and validate network communications from the device to any internal or external website. By pushing certificates to devices, you can secure access to networks,servers, secure e-mail communications etc., For example, you can deploy CA certificates to the managed devices if your organization uses S/MIME to connect to a network/server. The certificates pushed to the device ensures that the devices trusts the enterprise CA. This is applicable only for Non-Samsung devices(5.0 or later), devices must be enrolled as Fully Managed (COSU and COBO, or previously Device Owner) or Personally-Owned Work Profile (BYOD, or previously Profile Owner) and for Samsung devices(above 4.2).
The managed device must have a passcode set, for Certificate to be installed in the device.
| Profile Specification | Description |
|---|---|
| Certificate File | The file to be pushed to the managed devices |
| Password | This optional parameter must be entered if the certificate is password protected |
- The certificates are added only if the certificate files are not corrupt and the correct password is provided in case of password-protected certificates.
- On certificate expiry, upload the renewed certificate as a new certificate in the profile and then push it to the managed devices.
Frequently Asked Questions
- What type of certificates does the Android Certificate profile deploy? The Android Certificate profile deploys server CA certificates to managed Android devices, establishing device trust with the enterprise certificate authority to secure network communications.
- Why do I need to deploy CA certificates to Android devices through MDM? CA certificates secure and validate network communications such as corporate Wi-Fi and email connections. Deploying them through ManageEngine MDM ensures devices can authenticate with enterprise networks without manual installation.
- Which enrollment modes support the Android Certificate profile? The Certificate profile applies to Android devices enrolled as Fully Managed (COSU and COBO, or previously Device Owner) as well as Personally-Owned Work Profile (BYOD, or previously Profile Owner) devices in ManageEngine MDM.