Simple Certificate Enrollment Protocol (SCEP) configuration

BigFix MCM supports certificate management and certificate-based authentication through Simple Certificate Enrollment Protocol (SCEP). SCEP is the fastest and most secure way to provision certificates to all your MCM-managed devices. With SCEP, IT Admins can automate issuing certificates to the endpoints to provide access to corporate Wi-Fi, VPN, and secure e-mail through encryption.

Prerequisites

Upgrade to MCM 3.0

MCM v3.0 allows for certificate-based authentication using SCEP (Simple Certificate Enrollment Protocol) to manage devices within an on-premises infrastructure. To utilize this feature, upgrade the MDM server to MCM v3.0.

Network requirements

Allow all the ports and protocols necessary for communication between the NDES service and any supporting infrastructure in your environment. For example, the computer that hosts the NDES service needs to communicate with the CA, DNS servers, domain controllers, and possibly other services or servers within your environment, like Configuration Manager.

The device directly contacts the SCEP server to generate the certificate, therefore ensure the SCEP server is reachable from the device. It is not necessary for the SCEP server to be reachable to MDM.

TCP port 80: SCEP runs on TCP port 80; however, it can also run on a nonstandard TCP port. SCEP-based enrollment is configured in trustpoint mode. TCP port 80 is the default port used for SCEP and is configurable using the enrollment command.