Jamf Pro includes a built-in CA that issues client certificate identities that are used to enroll devices and to secure communication between Jamf Pro and enrolled devices. No configuration is necessary to use Jamf Pro's built-in CA for this purpose. The CA certificate and signing certificate are created and stored automatically.
During enrollment, devices communicate with the SCEP server to obtain the necessary certificates for device identification and secure communication with Jamf Pro.
If you do not want computers or mobile devices to communicate directly with a SCEP server and you are using the built-in CA, you can enable Jamf Pro as SCEP Proxy to issue device certificates via configuration profiles. For more information, see the Enabling Jamf Pro as SCEP Proxy technical paper.
The certificates issued from the built-in CA are not intended or available for use in additional workflows, such as VPN or Wi-Fi certificate-based authentication.