Signing emails with S/MIME SCEP certificate type Outlook app

Marcos Vázquez 21 Reputation points
2020-11-07T20:02:38.257+00:00

Hello,

I'm trying to sign emails from outlook app, deploying an application configuration profile like this:

38115-2020-11-07-20-52-04-window.png

The certificate is deployed to the Intune Company Portal via NDES server and previously, i deploy the trusted root certificate from the CA in the management profile. I also has uploaded to 0365 the SST certificate chain in order to trust this certificate from Outlook app.

I can see the certificate in the security settings in Outlook app but when i try to create an email i get an error: you have a problem with one of your SMIME certificates, and can't sign.

It seems to be all steps correct. I am using a trial tenant. What could be the cause?.

Thank you in advance.

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,787 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Crystal-MSFT 45,746 Reputation points Microsoft Vendor
    2020-11-09T04:21:08.997+00:00

    @Marcos Vázquez , For our issue, we can firstly manually download the S/MIME certificate and install on one client. Check if it is working well. This can identity if the certificate has any issue. Here is an article for the reference.
    https://www.ssl.com/how-to/installing-an-s-mime-certificate-and-sending-secure-email-with-outlook-on-windows-10/
    Note: Non-Microsoft link, just for the reference.

    If there's any update, feel free to let us know.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Marcos Vázquez 21 Reputation points
    2020-11-09T15:38:59.853+00:00

    Hello,

    I tried manually but same result. Here you can see the screenshots:

    1) The manually installed certificate is visible from Outlook app, so i understand the SST export to O365 to trust the local CA is working:
    38307-img-0001.png
    2) Here the details of the certificate. Signing is enabled. When i requested the certificate i intro this values:
    CN = as email address (user as email address format)
    SAN:
    -email = user email
    -UPN = user UPN
    38289-img-0002.png
    3) The result when i try to sign:
    38308-img-0003.png

    I dont know if i missmatch some step.

    Thanks.


  3. Marcos Vázquez 21 Reputation points
    2020-11-23T10:31:44.69+00:00

    @Crystal-MSFT , do you know if i can move this same thread to the O365 support in order to maintain the comment history?. Thanks.