Intune (Initial Setup)
Setting up Intune for the first time
Create a new Azure AD Application that can verify your Intune requests.
Register an application
In your Azure Portal, go to App Registrations and create a new Registration.
You may name it Foxpass-Intune-Verification and select this option 'Accounts in this organizational directory only ( only - Single tenant)'.
data:image/s3,"s3://crabby-images/055c7/055c7147ff0efefb7a4dc4a164602a5af567823b" alt="Register an application"
Register an application
Add permissions
Now, from the list in App Registrations, click on the newly created App. Go to the "API Permissions" page.
Click "Add a Permisson." In the window that appears, choose "Intune"
data:image/s3,"s3://crabby-images/033f9/033f91b8016d64ffac1cb619060da2099a39ed25" alt=""
Then choose Application permissions, and select "scep_challenge_provider"
Click the "Add permission" button.
Now add the Application.Read.All permisson. Click "Add a Permission" again.
Click Microsoft Graph
Click "Application permissions"
Then choose Application.Read.All
Push the "Add Permissions" button.
Back on the "API permissions" screen, click on the "Grant admin consent" button on the top of the Permissions page and click 'Yes'.
data:image/s3,"s3://crabby-images/28542/285427fbbe0acacbb98e810570685ee556b5b422" alt="Grant admin consent for Foxpass"
Grant admin consent for Foxpass
Copy Tenant ID, Client ID and Secret value
- Go to the 'Overview' section of your App and copy the Application (client) ID and Directory (tenant) ID.
- Go to the 'Certificates & secrets' section of your App and under 'Client secrets', click on the 'New client secret' button. Copy the secret value - this is your client's secret. Note - Make sure you copy the secret value and not the secret ID.
data:image/s3,"s3://crabby-images/25b42/25b42ec260bb12feec6db84a29a76013b640b6c0" alt="Copy secret value"
Copy secret value
Create a SCEP endpoint
- Go to the Foxpass Console's SCEP page, click on Create SCEP endpoint.
- Name - Give a name to your endpoint.
- Verification type - User
- Authentication type = 'Azure'
- Azure Tenant ID - Paste the Tenant ID copied from Azure
- Azure Client ID - Paste the Client ID copied from Azure
- Azure app client secret - Paste the secret copied from Azure
- Click 'Create' button.
data:image/s3,"s3://crabby-images/31b5d/31b5d6868f1924ada1aac7364b1851d77cdf561a" alt="Create Azure SCEP endpoint"
Create Azure SCEP endpoint
Updated 22 days ago