This article explains how to obtain a signing certificate from a Microsoft certificate authority (CA) using the Microsoft Management Console (MMC) and upload the certificate to Jamf Pro. When a computer or mobile device that needs a certificate checks in with Jamf Pro, the device communicates with the SCEP server to obtain the certificate. You can enable Jamf Pro to proxy this communication between a SCEP server and the devices in your environment to ensure devices do not need to access the SCEP server. When Jamf Pro is enabled as a SCEP Proxy, Jamf Pro communicates directly with the SCEP server to obtain certificates and install them on computers and mobile devices.
The procedure involves the following steps:
Configuring an External CA in Jamf Pro
Generating a Certificate Signing Request
Uploading the Certificate to Jamf Pro
Creating a Configuration Profile with a SCEP Payload