Onboard Windows devices with certificates using Workspace ONE UEM and SCEP
In this topic, you will learn how to deploy Portnox™ Cloud certificates to Windows devices via Workspace ONE UEM and SCEP.
Turn on the Portnox Cloud SCEP services
In this section, you will configure Portnox™ Cloud to provide SCEP services to your devices.
If you have previously turned on the Portnox Cloud SCEP services, skip to the later steps.
Portnox Cloud SCEP services let devices contact the Cloud SCEP server and get a unique certificate for the device or for the specific user of the device.
Download the root CA certificate from Portnox Cloud
In this section, you will download the Portnox™ Cloud root CA certificate from the Cloud portal.
You need the root CA certificate so that your managed devices can verify the validity of Cloud RADIUS servers, which have certificates signed by this root CA certificate. If the root CA certificate is not distributed to managed devices, some devices may show a security warning each time that the user connects to networks managed by Portnox Cloud.
Optional: Hand over information from the Portnox Cloud team to the Workspace ONE team
In this section, you will learn what information was collected in previous steps from Portnox Cloud, which is needed to configure Workspace ONE to work with Portnox Cloud.
If different people are responsible for managing Portnox Cloud and Workspace ONE, here is the information you need to hand over:
-
The URL of the Portnox Cloud SCEP server. For example, https://scep.portnox.com/b2973887-1274-45d4-91d0-4a342a861c76.
-
The password for the SCEP server.
-
The root CA certificate file in the Base-64 encoded X.509 format. For example, rootCertificate.cer.
Create the SCEP CA configuration and the SCEP request template
In this section, you will create the SCEP CA configuration and the SCEP request template in Workspace ONE UEM. This configuration and this template will be used by the profiles that you will create later.
Result: You created a configuration for the Portnox Cloud SCEP CA and the SCEP request template.


Create a user profile
In this section, you will create a user profile in Workspace ONE UEM for obtaining the SCEP certificate.
The user profile in Workspace ONE UEM is needed to obtain the SCEP certificate from the Portnox Cloud SCEP server for the current user or for the current device. The SCEP certificate is then used by the device profile for WiFi identification.
Result: You created a user profile for Portnox Cloud and Windows devices.

Create a device profile
In this section, you will create a device profile in Workspace ONE UEM with a Wi-Fi payload for secure Wi-Fi connections.
The device profile in Workspace ONE UEM is used to distribute the root CA certificate that you downloaded earlier from Portnox Cloud, as well as to push the Wi-Fi configuration on the basis of the SCEP certificate generated with the help of the user profile.
Result: You created a device profile for Portnox Cloud and Windows devices.

After you created your profiles, you can use your regular Workspace ONE UEM procedures to push them to managed computers immediately and see if they work correctly. For information on managing computers, pushing profiles, and troubleshooting, consult the Workspace ONE UEM documentation.




























