IntuneTroubleshooting

Wi-Fi or VPN profile not applying? Troubleshoot the SCEP/PKCS certificate chain in Intune

Trace a stuck Wi-Fi or VPN profile back through the certificate chain: trusted root, SCEP/PKCS profile, Certificate Connector and NDES, using the logs and event IDs Microsoft documents.

A certificate-based Wi-Fi or VPN profile that sits at Pending, or shows Succeeded while the device still can't connect, is rarely a Wi-Fi problem. The profile depends on a certificate, the certificate depends on a SCEP or PKCS profile, and that depends on a trusted root profile, a Certificate Connector and (for SCEP with a Microsoft CA) an NDES server. In this post I'll walk the chain from the admin center down to the device, using only the logs and event IDs Microsoft documents.

How this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it. 4. Verify the fix. 5. Prevent it next time. Toolbox: Event ID 36, Manage devices › Configuration, Intune › CertificateConnectors, autoupdate.msappproxy.net, /certsrv/mscep/mscep.dll.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it nexttimeTOOLBOXEvent ID 36Manage devices › ConfigurationIntune › CertificateConnectorsautoupdate.msappproxy.net/certsrv/mscep/mscep.dllHow this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it. 4. Verify the fix. 5. Prevent it next time. Toolbox: Event ID 36, Manage devices › Configuration, Intune › CertificateConnectors, autoupdate.msappproxy.net, /certsrv/mscep/mscep.dll.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it next timeTOOLBOXEvent ID 36Manage devices › ConfigurationIntune › CertificateConnectorsautoupdate.msappproxy.net/certsrv/mscep/mscep.dll
At a glance: how this guide is organised · 5 sections · 5 key tools

Symptoms#

  • The Wi-Fi or VPN profile reports Pending or Error for some or all devices, while unrelated profiles apply fine.
  • The SCEP or PKCS certificate profile shows errors in its device status, or the certificate never appears in the device's certificate store.
  • The profile reports Succeeded, but the device can't authenticate to the network and the RADIUS server logs a certificate it doesn't like.

Why it happens#

Intune installs a Wi-Fi or VPN profile that references a certificate profile only after that certificate is present on the device. Microsoft's own Wi-Fi troubleshooting guide spells out the dependency: if the Wi-Fi profile is linked to trusted root and SCEP profiles, both must be deployed to the device first. Anything that stops certificate issuance therefore shows up as a Wi-Fi or VPN failure. The usual culprits:

  • Subject name variables the device can't resolve. A device must support every variable in the profile; a SCEP profile using {{IMEI}} fails on a device without an IMEI, and user variables such as {{UserPrincipalName}} can't be resolved on user-less devices. Escaped special characters (\, \+ \; \=) in the CN produce a CSR that doesn't match the challenge, and the connector rejects it. Microsoft also advises against {{DeviceId}} in the subject on Windows.
  • Extended key usage mismatch. The EKU in the profile has to be present on the CA template too. Microsoft's example is an Any Purpose EKU set in the SCEP profile but missing from the template, which leaves the Wi-Fi profile waiting for a certificate that never matches.
  • Key size versus key storage. On Windows, 4096-bit keys are only supported in the software KSP; a profile that asks for 4096 bits in the TPM or in Windows Hello for Business fails.
  • Validity period. The profile value can be lower than the template's validity but never higher, and it must also be shorter than the remaining life of the issuing CA's certificate. Microsoft recommends at least five days.
  • Permissions. The connector's service account needs Read and Enroll on every template it issues from (plus Issue and Manage Certificates for revocation). For SCEP, the NDES application pool account also needs Read and Enroll on the SCEP templates and membership of IIS_IUSRS.
  • A stale connector. Each connector version is supported for six months after the next release and may stop working after 18 months. Automatic updates need TCP 443 to autoupdate.msappproxy.net.
  • NDES plumbing. IIS request filtering must allow long URLs (65534 bytes for both URL and query string), the SCEP application pool must be running, and the NDES server's Trusted Root store must contain root certificates only.

How to fix it#

  1. Check all three profiles for the same device. In the Intune admin center, under Devices › Manage devices › Configuration, open the trusted certificate profile, the SCEP or PKCS profile and the Wi-Fi/VPN profile in turn and look at the device status. Fix the earliest failing link; a Pending Wi-Fi profile with a failing SCEP profile is expected behaviour. Confirm all three are assigned to the same groups.
  2. Check connector health. Go to Tenant administration › Connectors and tokens › Certificate connectors. A deprecated connector shows a Warning; one past its grace period shows an Error and can stop working at any time. Update it by running the installer again on the server.
  3. Read the connector logs on the server. Open Event Viewer › Applications and Services Logs › Microsoft › Intune › CertificateConnectors. The Admin log has one event per request; the Operational log shows the steps in between. Event IDs are grouped by scenario:
    RangeScenarioEvents to look for
    1000–1999PKCS1000 request uploaded successfully; 1001 failed to fulfil or upload; 1052 failed to issue
    2000–2999PKCS import2001 failed to process an import request
    3000–3999Revocation3051 revoke failed
    4000–4999SCEP4000 processed and Intune notified; 4001 failed to process; 4005 challenge verification failed; 4007 CA didn't issue
    5000–5999Connector health5002 health upload failed, usually network
  4. For SCEP, confirm the device reaches NDES. On the NDES server, open the newest file under %SystemDrive%\inetpub\logs\LogFiles\W3SVC1 and look for GET requests to /certsrv/mscep/mscep.dll. Status 200 means the device connected. Status 500 points to a missing Impersonate a client after authentication user right for IIS_IUSRS. No entry at all means the request never arrived, so check the SCEP server URL, the Microsoft Entra application proxy or the firewall.
  5. Browse to the SCEP server URL yourself. Copy the URL from the profile and open it in a browser. The healthy answer is HTTP Error 403.0 – Forbidden. Microsoft's guide maps the other responses: a generic NDES page means the connector's policy module isn't installed correctly; 503 means the SCEP application pool is stopped (often because intermediate certificates sit in the Trusted Root store or the NDESPolicy certificate expired); 414 means request filtering wasn't raised to 65534; 500 points to a locked NDES service account or expired MSCEP-RA certificates; GatewayTimeout means the application proxy connector service isn't running.
  6. Fix the profile itself. Correct the subject name (wrap CN values containing commas in quotes), align the EKU with the template, use the software KSP for 4096-bit keys or drop to 2048, and keep the validity inside the template's limits. For KB5014754 strong mapping, add {{OnPremisesSecurityIdentifier}} as a URI SAN attribute; users and devices must be synced from Active Directory for Intune to resolve it.
  7. Trigger a retry. Devices retry a failed SCEP request on their next policy cycle. Sync from Settings › Accounts › Access work or school › Info › Sync or from the admin center rather than waiting.

Note: Starting with connector version 6.2510.3.2002, the SCEP validation service rejects certificate requests with extension OIDs that aren't on Microsoft's allow list. If a third-party tool or template adds custom extensions, expect verification failures after updating.

Verify the fix#

On a Windows device, open Event Viewer › Applications and Services Logs › Microsoft › Windows › DeviceManagement-Enterprise-Diagnostics-Provider › Admin. Event 36 with SCEP: Certificate request generated successfully confirms the request was built and lists the EKU, the NDES URL and the KSP that were used. When the Wi-Fi profile applies, you'll see events from WiFiConfigurationServiceProvider reporting The operation completed successfully. Then confirm the certificate and the profile:

PowerShell
# Device certificates issued by your CA, with their EKUs
Get-ChildItem Cert:\LocalMachine\My |
    Where-Object { $_.Issuer -like '*Contoso Issuing CA*' } |
    Select-Object Subject, NotAfter, @{n='EKU';e={$_.EnhancedKeyUsageList.FriendlyName -join ', '}}

# Wi-Fi profiles present on the device
netsh wlan show profiles

User certificates land in Cert:\CurrentUser\My instead. In Settings › Accounts › Access work or school › (account) › Info, the Wi-Fi area appears under Areas managed by Microsoft, and Settings › Network & Internet › Wi-Fi lists the network as saved. If the profile is on the device but the connection still fails, the cause is usually outside Intune: compare the certificate properties with what the RADIUS server expects and read its logs.

Prevent it next time#

  • Deploy the trusted root, certificate and Wi-Fi/VPN profiles to the same groups, and prefer user groups when you want certificates quickly after enrollment; device-targeted profiles wait for full device registration.
  • Pilot every change to a certificate profile with a small group. Editing the subject or SAN of an existing profile can trigger re-issuance for everyone targeted.
  • Check the connector status page regularly and keep automatic updates reachable. Install more than one connector; any connector that supports the same feature can serve a request.
  • Remember that renewal on iOS/iPadOS and macOS only happens inside the renewal threshold window; an expired certificate there requires excluding the device from the profile and re-adding it.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)