The Network Device Enrollment Service cannot submit the certificate request (The requested certificate template is not supported by this CA.). SCEP policy deployment failing for IOS only. Privacy | Are non-string non-aerophone instruments suitable for chordal playing? Specify the type of an alternative name for the SCEP server. What does it mean that a falling mass in space doesn't sense any force? Issue Complete these steps to restart the Intune Connector Service: On the connector-installed server, open the Services snap-in. 576), AI/ML Tool examples part 3 - Title-Drafting Assistant, We are graduating the updated button styling for vote arrows. everything went well, until I unplugged my device and turned it on. Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type. To identify problems for the communication and certificate provisioning workflow, review log files from both the Server infrastructure, and from devices. To troubleshoot Network Device Enrollment Service (NDES), see the following articles: Before proceeding, ensure you've met the prerequisites for using SCEP certificate profiles, including the deployment of a root certificate through a trusted certificate profile. 0 Kudos Share Device logs depend on the device platform: On-premises infrastructure that supports use of SCEP certificate profiles for certificate deployments includes the Microsoft Intune Certificate Connector, NDES that runs on a Windows Server, and the certification authority. The use case here is DEP/ADE enrolled devices. Profile Installation Failed. Also cloudd and SafariBookmarksSyncAgent throw those errors to the Console: This is often caused by an issue with the device itself. This articles gives guidance to help you troubleshoot and resolve issues with Simple Certificate Enrollment Protocol (SCEP) certificate profiles in Microsoft Intune. Is there anything we can do from an NDES or Enterprise CA point of view to resolve this? Connect and share knowledge within a single location that is structured and easy to search. This field is for validation purposes and should be left unchanged. What one-octave set of notes is most comfortable for an SATB choir to sing in unison/octaves? You can configure SCEP settings to obtain certificates from a certificate authority (CA) for Apple devices enrolled in a mobile device management (MDM) solution. The client receives the profile correctly from Intune, but the SCEP certificate fails to install. Certificate expiration notification threshold. "The SCEP Server returned an invalid response" when attempting to provision an iOS device through Relay Server. Source: Microsoft-Windows-NetworkDeviceEnrollmentService HTTPS requests / responses OK on the server side. Don't call it InTune. The certificate uploaded to the Trusted Root (TR) profile in Intune that the SCEP profile was using is different than the trusted root certificate installed on the NDES server. After the keys are created, change the template name under HKEY_LOCAL_Machine\Software\Microsoft\Cryptography\MSCEP to the custom template name that was created for SCEP and NDES. Can anyone help me? As soon as this happened it was noticed by our developers and quickly resolved. We've been noticing a new error though on an increasing number of devices. To subscribe to this RSS feed, copy and paste this URL into your RSS reader. Having the same issue when trying to reset iPhone after profile installation failure. Can I infer that Schrdinger's cat is dead without opening the box, if I wait a thousand years? Is there a place where adultery is a crime? Word to describe someone who is ignorant of societal problems, Solar-electric system not generating rated power, Securing NM cable when entering box with protective EMT sleeve. If rebooting the device does not help, do the DFU restore for the device. Is this something others have come across and did you fix it? Solution: Reboot the device or, if that doesn't help, do the DFU restore for the device. Note: Each MDM vendor implements these settings differently. Most browsers will initially say something about the SSL cert is not trusted. Profile installation failed The SCEP server returned an invalid response, Adding iOS devices to Apple Business Manager using Apple Configurator 2, Renewing an expiring Apple Automated Device Enrollment token, Moving DEP Enrolled Apple Devices from Another MDM Server to Miradore, How to Configure Apple Volume Purchase Program (VPP) in Miradore, How to manage licenses for apps purchased through Apple Business Manager, How to Invite Users to Apple Volume Purchase Program. The error message seen from the devices is rather vague: I have attempted to model my CSR handling based on Simple Certificate Enrollment Protocol Overview and the following Ruby sample code (found here and elsewhere): Finally, here is my implementation using Node.js and node-forge: Can anyone point out what I'm doing wrong here? How to deal with "online" status competition at work? cloudd: nw_endpoint_flow_validate_delegation [C392.1 IPv4#44dcd954:443 in_progress socket-flow (satisfied (Path is satisfied), interface: utun0, ipv4, ipv6, dns)] Network Delegation Failure: Invalid Bundle ID "com.apple.SafariBookmarksSyncAgent" [M] US Desc: The SCEP server returned an invalid response. Maybe it was possible in the past but in January, 2020 an iPhone I am working on does not show this option and iTunes on a computer gives this error: "This iPhone is supervised by another computer and cannot be used with this computer.". Supported operating systems and channels: iOS, iPadOS, Shared iPad device, macOS device, macOS user, tvOS. "The request was for a certificate template that is not supported by the Active Directory Certificate Services Policy: