- In Jamf Pro, click Settings in the sidebar.
- In the Global section, click PKI certificates .
- Click Management Certificate Template.
- Click External CA.
- Check Enable Jamf Pro as SCEP Proxy for configuration profiles.
- Enter the base URL for the SCEP server.Note:
If you are using Jamf Cloud and want to establish communication over HTTPS to your SCEP server, you must use a third-party SSL certificate. If you are using an on-premise Jamf Pro server and an on-premise CA, ensure the server is trusted through the Java CA certificates.
- Enter a name for the instance.
- (Optional) Enter a subject. You can also enter the subject in the configuration profile.
- Choose "Dynamic-Microsoft CA" from the Challenge Type pop-up menu, and then enter the required information.