# Keep all calls in an Intune SCEP request on the same NDES server

> Can an NDES load balancer send successive calls from one Intune SCEP request to different backends?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-566-keep-all-calls-in-an-intune-scep-request-on-the-same-ndes-server/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:30+00:00
- Modified: 2026-09-10T02:14:31+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

Can an NDES load balancer send successive calls from one Intune SCEP request to different backends?

## Potentially affected

Apply this review to Intune SCEP profiles using multiple NDES endpoints or a virtualized enrollment URL. Inspect backend selection during one enrollment request, not just whether each server responds independently.

## DSE recommendation

Have the load-balancer and PKI owners agree on how the full three-call sequence stays with one server.

## Article

## Source facts

An Intune SCEP request makes three NDES calls: capability discovery, public-key retrieval, and request submission. All three must reach the same actual NDES server. A load balancer that changes the backend during that sequence causes the request to fail, even behind one virtual URL. After failure, the device retries during its next policy cycle. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-configuration/certificates/scep-profiles).

## Applicability

Apply this review to Intune SCEP profiles using multiple NDES endpoints or a virtualized enrollment URL. Inspect backend selection during one enrollment request, not just whether each server responds independently.

## DSE recommendation

Have the load-balancer and PKI owners agree on how the full three-call sequence stays with one server. Include planned backend maintenance and failure behavior in that design. Avoid marking the service ready based only on a reachable virtual address or three successful tests that used unrelated enrollment attempts.

## Verification

Capture a controlled enrollment’s sanitized routing evidence and correlate its three stages with backend identity. Confirm successful issuance when the intended server remains available, then assess a safely simulated backend disruption against the documented retry behavior. Retain request timing and selected backend without copying challenge material or private keys. Investigate intermittent failures before adding more endpoints or increasing deployment scope.

## Official references

[Microsoft Learn: Use SCEP certificate profiles with Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-configuration/certificates/scep-profiles).

## Primary reference

- Name: Use SCEP certificate profiles with Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-configuration/certificates/scep-profiles
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Keep all calls in an Intune SCEP request on the same NDES server,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-566-keep-all-calls-in-an-intune-scep-request-on-the-same-ndes-server/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
