A certificate-based Wi-Fi or VPN profile that sits at Pending, or shows Succeeded while the device still can't connect, is rarely a Wi-Fi problem. The profile depends on a certificate, the certificate depends on a SCEP or PKCS profile, and that depends on a trusted root profile, a Certificate Connector and (for SCEP with a Microsoft CA) an NDES server. In this post I'll walk the chain from the admin center down to the device, using only the logs and event IDs Microsoft documents.
Symptoms#
- The Wi-Fi or VPN profile reports Pending or Error for some or all devices, while unrelated profiles apply fine.
- The SCEP or PKCS certificate profile shows errors in its device status, or the certificate never appears in the device's certificate store.
- The profile reports Succeeded, but the device can't authenticate to the network and the RADIUS server logs a certificate it doesn't like.
Why it happens#
Intune installs a Wi-Fi or VPN profile that references a certificate profile only after that certificate is present on the device. Microsoft's own Wi-Fi troubleshooting guide spells out the dependency: if the Wi-Fi profile is linked to trusted root and SCEP profiles, both must be deployed to the device first. Anything that stops certificate issuance therefore shows up as a Wi-Fi or VPN failure. The usual culprits:
- Subject name variables the device can't resolve. A device must support every variable in the profile; a SCEP profile using
{{IMEI}}fails on a device without an IMEI, and user variables such as{{UserPrincipalName}}can't be resolved on user-less devices. Escaped special characters (\,\+\;\=) in the CN produce a CSR that doesn't match the challenge, and the connector rejects it. Microsoft also advises against{{DeviceId}}in the subject on Windows. - Extended key usage mismatch. The EKU in the profile has to be present on the CA template too. Microsoft's example is an Any Purpose EKU set in the SCEP profile but missing from the template, which leaves the Wi-Fi profile waiting for a certificate that never matches.
- Key size versus key storage. On Windows, 4096-bit keys are only supported in the software KSP; a profile that asks for 4096 bits in the TPM or in Windows Hello for Business fails.
- Validity period. The profile value can be lower than the template's validity but never higher, and it must also be shorter than the remaining life of the issuing CA's certificate. Microsoft recommends at least five days.
- Permissions. The connector's service account needs Read and Enroll on every template it issues from (plus Issue and Manage Certificates for revocation). For SCEP, the NDES application pool account also needs Read and Enroll on the SCEP templates and membership of IIS_IUSRS.
- A stale connector. Each connector version is supported for six months after the next release and may stop working after 18 months. Automatic updates need TCP 443 to
autoupdate.msappproxy.net. - NDES plumbing. IIS request filtering must allow long URLs (65534 bytes for both URL and query string), the SCEP application pool must be running, and the NDES server's Trusted Root store must contain root certificates only.
How to fix it#
- Check all three profiles for the same device. In the Intune admin center, under Devices › Manage devices › Configuration, open the trusted certificate profile, the SCEP or PKCS profile and the Wi-Fi/VPN profile in turn and look at the device status. Fix the earliest failing link; a Pending Wi-Fi profile with a failing SCEP profile is expected behaviour. Confirm all three are assigned to the same groups.
- Check connector health. Go to Tenant administration › Connectors and tokens › Certificate connectors. A deprecated connector shows a Warning; one past its grace period shows an Error and can stop working at any time. Update it by running the installer again on the server.
- Read the connector logs on the server. Open Event Viewer › Applications and Services Logs › Microsoft › Intune › CertificateConnectors. The Admin log has one event per request; the Operational log shows the steps in between. Event IDs are grouped by scenario:
Range Scenario Events to look for 1000–1999 PKCS 1000 request uploaded successfully; 1001 failed to fulfil or upload; 1052 failed to issue 2000–2999 PKCS import 2001 failed to process an import request 3000–3999 Revocation 3051 revoke failed 4000–4999 SCEP 4000 processed and Intune notified; 4001 failed to process; 4005 challenge verification failed; 4007 CA didn't issue 5000–5999 Connector health 5002 health upload failed, usually network - For SCEP, confirm the device reaches NDES. On the NDES server, open the newest file under
%SystemDrive%\inetpub\logs\LogFiles\W3SVC1and look for GET requests to/certsrv/mscep/mscep.dll. Status 200 means the device connected. Status 500 points to a missing Impersonate a client after authentication user right for IIS_IUSRS. No entry at all means the request never arrived, so check the SCEP server URL, the Microsoft Entra application proxy or the firewall. - Browse to the SCEP server URL yourself. Copy the URL from the profile and open it in a browser. The healthy answer is HTTP Error 403.0 – Forbidden. Microsoft's guide maps the other responses: a generic NDES page means the connector's policy module isn't installed correctly; 503 means the SCEP application pool is stopped (often because intermediate certificates sit in the Trusted Root store or the NDESPolicy certificate expired); 414 means request filtering wasn't raised to 65534; 500 points to a locked NDES service account or expired MSCEP-RA certificates; GatewayTimeout means the application proxy connector service isn't running.
- Fix the profile itself. Correct the subject name (wrap CN values containing commas in quotes), align the EKU with the template, use the software KSP for 4096-bit keys or drop to 2048, and keep the validity inside the template's limits. For KB5014754 strong mapping, add
{{OnPremisesSecurityIdentifier}}as a URI SAN attribute; users and devices must be synced from Active Directory for Intune to resolve it. - Trigger a retry. Devices retry a failed SCEP request on their next policy cycle. Sync from Settings › Accounts › Access work or school › Info › Sync or from the admin center rather than waiting.
Note: Starting with connector version 6.2510.3.2002, the SCEP validation service rejects certificate requests with extension OIDs that aren't on Microsoft's allow list. If a third-party tool or template adds custom extensions, expect verification failures after updating.
Verify the fix#
On a Windows device, open Event Viewer › Applications and Services Logs › Microsoft › Windows › DeviceManagement-Enterprise-Diagnostics-Provider › Admin. Event 36 with SCEP: Certificate request generated successfully confirms the request was built and lists the EKU, the NDES URL and the KSP that were used. When the Wi-Fi profile applies, you'll see events from WiFiConfigurationServiceProvider reporting The operation completed successfully. Then confirm the certificate and the profile:
# Device certificates issued by your CA, with their EKUs
Get-ChildItem Cert:\LocalMachine\My |
Where-Object { $_.Issuer -like '*Contoso Issuing CA*' } |
Select-Object Subject, NotAfter, @{n='EKU';e={$_.EnhancedKeyUsageList.FriendlyName -join ', '}}
# Wi-Fi profiles present on the device
netsh wlan show profilesUser certificates land in Cert:\CurrentUser\My instead. In Settings › Accounts › Access work or school › (account) › Info, the Wi-Fi area appears under Areas managed by Microsoft, and Settings › Network & Internet › Wi-Fi lists the network as saved. If the profile is on the device but the connection still fails, the cause is usually outside Intune: compare the certificate properties with what the RADIUS server expects and read its logs.
Prevent it next time#
- Deploy the trusted root, certificate and Wi-Fi/VPN profiles to the same groups, and prefer user groups when you want certificates quickly after enrollment; device-targeted profiles wait for full device registration.
- Pilot every change to a certificate profile with a small group. Editing the subject or SAN of an existing profile can trigger re-issuance for everyone targeted.
- Check the connector status page regularly and keep automatic updates reachable. Install more than one connector; any connector that supports the same feature can serve a request.
- Remember that renewal on iOS/iPadOS and macOS only happens inside the renewal threshold window; an expired certificate there requires excluding the device from the profile and re-adding it.