Deploying a SCEP Profile

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

For computers with macOS 14 or later, you must deploy a SCEP profile alongside the Single Sign-on Extension profile for Platform SSO to function properly.

Requirements

You must generate a SCEP URL and secret key in your Okta Admin Console before proceeding in Jamf Pro. For more information, see Configure Okta as a CA with Static SCEP challenge for macOS with Jamf Pro from Okta.

  1. In Jamf Pro, click Computers in the sidebar.
  2. Click Configuration profiles in the sidebar.
  3. Click New.
  4. Click the SCEP payload.
  5. Click Configure.
  6. In the URL field, enter the static SCEP URL generated in your Okta Admin Console.
  7. In the Name field, enter a display name for the SCEP instance.
  8. Choose 7 days from the pop-up menu under Redistribute Profile.
  9. In the Subject field, enter the following value: CN=$COMPUTERNAME $PROFILE_IDENTIFIER
  10. Under Subject Alternative Names, ensure Challenge Type is set to Static.
  11. In the Challenge and Verify Challenge fields, enter the challenge secret from your Okta portal.
  12. In the Retries field, ensure the value is set to 0.
  13. In the Retry Delay field, ensure the value is set to 0.
  14. Choose 2048 from the Key Size pop-up menu.
  15. Deselect the Allow export from keychain checkbox.
  16. Select the Allow all apps access checkbox.
  17. Click the Scope tab, and then configure the target devices or device groups.
  18. Click Save in the bottom-right corner of the pane.

The configuration profile is deployed to computers in scope.