# Simple Certificate Enrollment Protocol (SCEP)
Last updated: August 14, 2026
This page explains how to configure the Simple Certificate Enrollment Protocol (SCEP) profile for tvOS devices in MDM. SCEP enables certificate-based authentication for services like Wi-Fi, VPN, and encrypted email, eliminating manual certificate distribution for IT administrators in large organizations. Learn how SCEP differs from the standard Certificate profile, understand how devices contact the SCEP server directly to generate client certificates, and find a complete reference for all SCEP profile settings including server URL, challenge type, key size, and subject attributes.
Simple Certificate Enrollment Protocol (SCEP) is a protocol standard used for certificate management. SCEP is predominantly used for certificate-based authentication, whereby access to services such as Wi-Fi, VPN, and securing email through encryption is carried out using certificates.
The major advantages of certificate-based authentication are:
- Zero-user intervention as users are authenticated via certificates.
- Secure network communication as the data is encrypted and authenticated using certificates.
However, manually distributing certificates is a cumbersome task for IT administrators in large-scale organizations. SCEP helps network administrators easily install certificates on devices. SCEP provides a simplified and scalable method for handling certificates in large organizations. The difference between Certificate and SCEP is that the SCEP policy is used for distributing client certificates to devices, while the Certificate policy distributes CA certificates to devices.
The device directly contacts the SCEP server to generate the certificate; therefore, ensure the SCEP server is reachable from the device. It is not necessary for the SCEP server to be reachable from MDM.
## Configuring SCEP in MDM
1. You can verify server details such as the enrollment challenge password from **http://<your-server>/CertSrv/mscep_admin** and **http://<Your-Server>/crtsrv/mscep/mscep.dll**
| PROFILE SETTINGS | DESCRIPTION |
|---|---|
| SCEP Configuration Name | The user-defined configuration name, which is used to refer to this configuration in other configurations such as Wi-Fi, VPN, etc. |
| SCEP SETTINGS | |
| Server URL | The URL to be specified on the device to obtain a certificate. Provide the HTTP Server URL if the SCEP server is within the organization network and not exposed to external networks. The certificate is requested through this URL.
For [NDES](http://social.technet.microsoft.com/wiki/contents/articles/9063.network-device-enrollment-service-ndes-in-active-directory-certificate-services-ad-cs.aspx), the server URL format is: **http://<your-server>/CertSrv/mscep/mscep.dll** |
| Certificate Authority Name | Specify the name of the Certificate Authority issuing certificates. |
| Subject | Specify the details (%username%, %email%, %domainname%, %devicename%) to map the corresponding details on the device. |
| Subject Alternative Name Type | Specify the alternate details (RFC 822 Name, DNS Name, Uniform Resource Identifier). |
| Subject Alternative Name Type Value **(Can be configured only if Subject Alternative Name Type is configured)** | Specify the value for the alternative name type. |
| NT Principal Name | Specify the NT Principal Name used in the organization. |
| Maximum Number of Failed Attempts | Number of attempts to obtain the certificate from the CA. |
| Time interval between attempts | Time to wait before subsequent attempts to obtain a certificate. |
| Challenge Type | A pre-shared secret key provided by the CA, which adds an additional layer of security. |
| Enrollment Challenge Password | Provide the challenge password to be used. The challenge password can be identified as explained [here](https://www.manageengine.com/mobile-device-management/help/profile_management/tvos/mdm_tvos_scep.html#scep). |
| Key Size | Specify whether the key is 1024 or 2048 bits. |
| Use as Digital Signature | Enabling ensures the certificate can be used as a digital signature. |
| Use for Key Encipherment | Enabling ensures the certificate can be used for key encipherment. |
## Frequently Asked Questions
### What's the difference between the Certificate profile and SCEP?
The Certificate profile distributes CA certificates to devices, while SCEP is used to distribute client certificates, letting devices contact the SCEP server directly to generate their own certificate.
### Does the SCEP server need to be reachable from MDM?
No. The device contacts the SCEP server directly to generate the certificate, so only the device-to-SCEP-server connection needs to be reachable, not MDM-to-SCEP-server.
### Where can I find the enrollment challenge password for NDES?
You can verify server details, including the enrollment challenge password, at http://<your-server>/CertSrv/mscep_admin.