Setup Intune Certificate Connector. Instructions are lacking.

ComputerHabit 861 Reputation points
2024-03-20T18:11:54.2066667+00:00

I am trying to follow this article to setup the Intune Cert Connector.

https://video2.skills-academy.com/en-us/mem/intune/protect/certificate-connector-prerequisites#certificate-connector-service-account

What does this mean?
User's image

I follow the link to the article.
https://video2.skills-academy.com/en-us/mem/intune/protect/certificates-imported-pfx-configure#import-pfx-certificates

It talks about PFX import. Do I need PFX import for Certificate Connector? I thought the point of Cert Connector was to Issue certs.

This isn't clear to me at all what I need to do at this step.

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
370 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,664 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Crystal-MSFT 45,656 Reputation points Microsoft Vendor
    2024-03-21T01:31:19.31+00:00

    @ComputerHabit, Thanks for posting in Q&A. In fact, Certificate Connector will be used when we deploy SCEP, PKCS certificate via Intune. It also be used when we import PFX certificate to Intune. Based on my understanding, the permission is used when we want to import PFX Certificates to Intune.

    If we only want to deploy SCEP certificate, the permission is not required.

    https://video2.skills-academy.com/en-us/mem/intune/protect/certificates-scep-configure

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Pavel yannara Mirochnitchenko 12,391 Reputation points MVP
    2024-03-21T06:29:49.1+00:00

    This thingy is pain in the ass, excuse my french. Have you considered to go with Cloud PKI which is part of Intune Suite? It will cost you like 2-3e/user/month.

    https://video2.skills-academy.com/en-us/mem/intune/protect/microsoft-cloud-pki-overview


  3. ComputerHabit 861 Reputation points
    2024-03-21T14:45:33.8133333+00:00

    After I read the choose your own adventure of documentation, I understand that there are three types of deployments of certs. PKCS (templates from certsrv), SCEP (still not sure what for) and PFX distribution (I guess to deploy same cert to lots of users.)

    The docs just drive me nuts because they mention ensuring something is in place but it can't be in place because you're setting it up.

    It might have been less confusing to not include that line at all.