Project

General

Profile

Actions

Bug #12574

closed

Task #12481: 6.4.0 overall testing

SCEP enrollment failing on Azure AD provisioned users

Added by Navod Zoysa 2 months ago. Updated 22 days ago.

Status:
Closed
Priority:
Critical
Assignee:
Start date:
13/02/2025
Due date:
17/02/2025
% Done:

100%

Estimated time:
Device Type:
Windows
Component:
Windows Agent
Type:
Windows

Description

Environment details
6.3.0 staging server

Prerequisites
Azure AD Enrollment Configuration - https://docs.entgra.io/uem/6.3.0/configurations/#azure-ad-enrollment

Steps
Enroll a Windows device using one of the Azure AD integrated enrollments - https://docs.entgra.io/uem/6.3.0/enrollment/#windows-azure-ad-integrated-enrollment

Description
OTP generated against the Azure AD provisioned users are getting a 403 when calling the SCEP endpoint

Result
Getting a 403 when calling the SCEP endpoint from the agent application

"POST /api/device-mgt/windows/v1.0/agent/certificate HTTP/1.1" 403

TID: [-1234] [api/device-mgt/windows/v1.0] [2025-02-10 16:07:32,930] ERROR {io.entgra.device.mgt.core.webapp.authenticator.framework.WebappAuthenticationValve} - Unauthorized message from user mdm
Actions

Also available in: Atom PDF