# MDM configuration

Configure the MDM with the endpoint URL and its **CA bundle**. Use separate endpoints for populations with different validity, naming, or key-usage requirements.

Deploy the CA chain in the same device profile as the SCEP payload. A device that does not trust the issuer will enroll and then fail to use the certificate for anything.

## Apple — Jamf Pro, Kandji, Mosyle, raw payloads

In a `com.apple.security.scep` payload:

| Key       | Value                                                                     |
| --------- | ------------------------------------------------------------------------- |
| URL       | `https://pki.example.com/scep/<endpoint-id>`                           |
| Challenge | The challenge password, or a dynamic challenge where the MDM supports one |
| Key Size  | 2048 or greater                                                           |
| Key Usage | Digital signature and key encipherment                                    |
| Subject   | Whatever your endpoint's subject pattern permits                          |

Jamf Pro can fetch a unique challenge per device — see [Jamf Pro](/protocols/scep/jamf). Kandji and Mosyle take a challenge in the payload, so use a shared secret or mint one-time challenges from automation.

## Windows — Intune and MDM CSP

See [Microsoft Intune](/protocols/scep/intune) for connecting the tenant. The critical detail is the URL:

```text
✓  https://pki.example.com/scep/<endpoint-id>
✗  https://pki.example.com/scep/<endpoint-id>/pkiclient.exe
```

Do not add `/pkiclient.exe`; Windows appends it. Adding it produces `/pkiclient.exe/pkiclient.exe` and error `0x800700CE`.

## Workspace ONE UEM and Ivanti Neurons

Configure a **generic SCEP** certificate authority with the endpoint URL and the downloaded CA/RA bundle. Prefer one-time challenges; fall back to the shared secret only where the product cannot retrieve a unique challenge per device.

## Policy sources

| The endpoint decides                       | The MDM profile decides                             |
| ------------------------------------------ | --------------------------------------------------- |
| Certificate validity                       | Subject and subject alternative names requested     |
| Renewal window                             | Key type and size                                   |
| Which extended key usages may be requested | Which of the permitted usages this profile asks for |
| Which subjects and names are acceptable    | When the device attempts renewal                    |

SimpleSCEP ignores the MDM validity setting. Requests for unpermitted usages are rejected and recorded under **Recent enrollments**. See [Issuance profiles and key usages](/platform/profiles).

## Before rolling out to a fleet

1. Enroll one device and confirm the certificate appears on the Certificates page with the subject and usages you expect.
2. Revoke that certificate and confirm it appears on the CRL — see [Revocation, CRL and OCSP](/platform/revocation).
3. Check **Recent enrollments** for refusals before expanding the rollout.
