To establish the necessary certificate trust stores for the devices to successfully enroll with Intune, the following Trusted certificate profiles need to be configured:
Computers trusted root store - Root CA
Computers trusted intermediate store - Root CA
Computers trusted intermediate store - Intermediate CA
Follow this guide to configure each of the trusted certificate profiles:
- Navigate to the Azure Endpoint manager (https://endpoint.microsoft.com/).
- Navigate to Devices => Configuration Profiles, and select Create profile.
- Perform the following settings:
- Set Platform to Windows 10 or later.
- Set Profile type to templates.
- Select Template name to trusted certificate and click Create.
- Enter a profile name and optionally a description, then click Next.
- Upload the certificate that should be trusted, in DER format, and specify the 'Destination store'. Then click on next.
- For Root CA in trusted root store: upload the root CA certificate and set Destination store to Computer certificate store - Root.
- For Root CA in trusted intermediate store: upload the root CA certificate and set Destination store to Computer certificate store - Intermediate.
- For Intermediate CA in trusted intermediate store: upload the intermediate CA certificate and set Destination store to Computer certificate store - Intermediate.
- Configuring the access rights to this profile can be done either by applying it to all devices or by applying it to a selected group that the users requesting certificates via Intune will be a part of. Once the assignments have been configured click on next.
- If no device limitation is required, configuration of the accessibility rules can be skipped. Click on Next to proceed.
- Review your settings and verify that they are correct and then click on Create.