{"id":85633,"date":"2023-06-05T13:09:51","date_gmt":"2023-06-05T17:09:51","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=85633"},"modified":"2023-11-01T15:27:17","modified_gmt":"2023-11-01T19:27:17","slug":"create-mac-or-ios-scep-profiles-policy","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/create-mac-or-ios-scep-profiles-policy","title":{"rendered":"Create a Mac or iOS SCEP Profiles Policy"},"content":{"rendered":"\n

This policy configures Simple Certificate Enrollment Protocol (SCEP) for your macOS and iOS devices. SCEP makes issuing digital certificates easier, more secure, and scalable. You\u2019ll need a Certificate Authority (CA) to issue the device credentials using SCEP. The fields in this SCEP Profiles policy are added to the SCEP payload. <\/p>\n\n\n\n

The macOS policy works on all JumpCloud macOS supported operating systems<\/a> that are enrolled in Mobile Device Management (MDM). The iOS policy works on all JumpCloud iOS and iPadOS supported operating systems on devices that are enrolled in MDM.   <\/p>\n\n\n\n

To create a macOS or iOS SCEP Profiles Policy<\/strong>:<\/p>\n\n\n\n

    \n
  1. Log in to the JumpCloud Admin Portal<\/a>.<\/li>\n\n\n\n
  2. Go to DEVICE MANAGEMENT > Policy Management<\/strong>.<\/li>\n\n\n\n
  3. In the All<\/strong> tab, click (+<\/strong>).<\/li>\n\n\n\n
  4. On the New Policy panel, select the Mac<\/strong> or the iOS <\/strong>tab.<\/li>\n\n\n\n
  5. Select the Mac or iOS SCEP Profiles<\/strong> policy from the list, then click configure<\/strong>.<\/li>\n\n\n\n
  6. (Optional) Enter a new name for the policy or keep the default. Policy names must be unique.<\/li>\n\n\n\n
  7. For Policy Notes<\/strong>, enter details like when you created the policy, where you tested it, and where you deployed it.<\/li>\n\n\n\n
  8. (Optional) Enter a Base64 encoded string in the Fingerprint<\/strong> field.\n
      \n
    1. You will need to convert the current SHA1 or SHA256 fingerprint, represented as a series of hexadecimal values, to a Base64 encoding of a “bytes” object. From the macOS Terminal, run the following command, replacing the fingerprint value with your Certificate Authority\u2019s:\n