GuideInformationBusiness ContinuityIT

Check reverse-proxy request handling before publishing Intune SCEP

Can a standard preauthenticated reverse-proxy configuration carry Intune SCEP enrollment requests?

Governed cloud identity system with connected service and lifecycle nodes.
DSE visual intelligenceIdentity & cloudGuide · 1 min read
Executive summary

What you need to know

Can a standard preauthenticated reverse-proxy configuration carry Intune SCEP enrollment requests?

Potentially affected

Use this check for an Intune SCEP design backed by Microsoft AD CS and NDES. Review the exact external publication path, including every proxy that handles the enrollment request.

DSE recommendation

Give the proxy owner the SCEP-specific authentication and request-length requirements before selecting a generic web-application template.

Source facts

Microsoft says SCEP cannot use reverse-proxy preauthentication; the NDES publication must use passthrough. The request carries certificate-request data in its query string, and a third-party proxy must accommodate a URI up to 40 KB. The Intune connector’s policy module validates enrollment requests; directly browsing its published NDES URL returns a forbidden response. Microsoft Learn.

Applicability

Use this check for an Intune SCEP design backed by Microsoft AD CS and NDES. Review the exact external publication path, including every proxy that handles the enrollment request.

DSE recommendation

Give the proxy owner the SCEP-specific authentication and request-length requirements before selecting a generic web-application template. Preserve the Intune policy-module validation rather than interpreting passthrough as permission to remove enrollment controls. Define the expected direct-browser response separately from a managed device’s enrollment result.

Verification

Use a controlled Intune-managed device to request the intended certificate through the external path. Inspect sanitized proxy and enrollment events to distinguish request rejection from certificate-validation failure. Confirm that ordinary direct browsing does not become an issuance test or a reason to bypass the module. Record the approved proxy limits and actual certificate outcome without retaining private keys or challenge material.

Official references

Microsoft Learn: Configure infrastructure to support SCEP certificate profiles with Microsoft Intune.

Primary reference

Review the official source

Configure infrastructure to support SCEP certificate profiles with Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE