{"id":84787,"date":"2023-06-05T13:11:25","date_gmt":"2023-06-05T17:11:25","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=84787"},"modified":"2024-08-08T14:31:34","modified_gmt":"2024-08-08T18:31:34","slug":"manage-conditional-access-policy-certificates","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/manage-conditional-access-policy-certificates","title":{"rendered":"Manage Conditional Access Policy Certificates for Desktop"},"content":{"rendered":"\n
Conditional Access Policies let you relax, restrict, or deny user access to resources based on conditions that you set. Unmanaged or managed devices are conditions you can use to determine how users access the User Portal and SSO applications. <\/p>\n\n\n\n
To use a policy with a device condition, you need to distribute device certificates to your desktop devices. Device certificates for desktops allow authentication mechanisms to recognize if login requests are coming from JumpCloud managed devices.<\/p>\n\n\n\n
<\/p><\/div>
Looking to enforce device trust on mobile devices? See Get Started: Mobile Device Trust<\/a> to learn more.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n For information such as supported browsers for each supported OS, see Get Started: Conditional Access Policies<\/a>. <\/p>\n\n\n\n Prerequisites:<\/strong><\/p>\n\n\n\n Considerations:<\/strong><\/p>\n\n\n\n Distribute device certificates from the Conditional Policies Settings page or when you create your first policy that uses a device condition. See Configure a Conditional Access Policy<\/a> to learn how to distribute certificates when you create your first device-based policy. <\/p>\n\n\n\n To distribute a device certificate from the Conditional Policies Settings page<\/strong>: <\/p>\n\n\n\n You can remove global device certificates after you\u2019ve distributed them. When you disable Global Device Certificates, existing policies aren\u2019t updated, and any custom MacOS Keychain Application Access<\/a> configurations are removed. To make sure users have uninterrupted access to their resources, disable policies with a device condition before you remove global device certificates. Learn how to disable a policy in Configure a Conditional Access Policy<\/a>. <\/p>\n\n\n\n To remove global device certificates<\/strong>:<\/p>\n\n\n\n\n
\n
Storage Location of Global Device Certificates<\/h2>\n\n\n\n
Linux<\/h3>\n\n\n\n
\n
Mac<\/h3>\n\n\n\n
\n
Windows<\/h3>\n\n\n\n
\n
Distributing Global Device Certificates <\/h2>\n\n\n\n
\n
Removing Global Device Certificates<\/h2>\n\n\n\n