Nora
Blake

Enhanced macOS SCEP Policy Settings in Hexnode UEM

Nora Blake

Jul 29, 2026

3 min read

macOS SCEP

Securing enterprise Macs with certificates for Wi-Fi, VPNs, and internal applications is a non-negotiable security requirement. However, for IT admins, integrating a growing macOS fleet with existing on-premises Certificate Authorities (CAs) or diverse third-party PKI providers often involves frustrating routing issues and complex manual workarounds.

To eliminate this friction, Hexnode UEM has updated its macOS SCEP (Simple Certificate Enrollment Protocol) policy settings. You now have fine-grained control over your specific server environments and CA architecture, making zero-touch certificate deployment completely effortless.

What’s New?

We have introduced dedicated environment and provider controls directly inside the SCEP Policy workflow for macOS. IT administrators can now explicitly configure the Certificate Authority provider and server environment for macOS SCEP profiles.

1. Granular Certificate Authority (CA) Selection

You no longer have to force-fit your CA. Hexnode now provides explicit topology choices:

  • Microsoft AD CS: Dedicated support for Microsoft Active Directory Certificate Services.
  • Generic: Instantly connect with any third-party, SCEP-compliant CA provider.

2. Precise Server Type Configuration

Specify your exact hosting topology to streamline request routing. You can now choose between:

  • On-prem: Tailored specifically for localized infrastructure.
  • Cloud: Optimized for modern, cloud-hosted PKI setups.

The Value for IT Admins

  • Fits Any Environment: Whether you are running legacy on-premises servers or modern cloud infrastructure, the updated SCEP policy adapts to your exact setup.
  • Agnostic Provider Support: You are never locked into a single ecosystem. Connect natively to Microsoft AD CS or plug in standard SCEP protocols for any third-party vendor.
  • Hands-Free Device Security: Once configured, managed macOS devices automatically request and receive certificates through SCEP. End-users can then securely access corporate Wi-Fi and VPNs using certificate-based authentication without manually installing certificates or contacting the IT help desk.

Real-World Use Case

Scenario: Onboarding 200 new MacBooks that require access to internal resources via an on-premises Microsoft AD CS infrastructure.

With the new enhancements, administrators can select Microsoft AD CS as the Certificate Authority and specify whether it is hosted on-premises or in the cloud, simplifying configuration for Microsoft PKI environments.

With the new enhancements, an IT admin simply creates a macOS SCEP policy in Hexnode, selects Microsoft AD CS as the CA, and chooses On-prem as the server type. Hexnode handles the certificate requests seamlessly in the background.

Once the SCEP certificate is enrolled and the corresponding Wi-Fi or VPN profile is applied, users can authenticate to corporate resources using certificate-based authentication without manually installing certificates.

Availability & Quick Setup

This feature is available immediately for all macOS devices managed via Hexnode UEM.

How to configure it:

  • Navigate to Policies in your Hexnode UEM console.
  • Go to macOS > Security > SCEP.
  • Define your Certificate Authority and Server Type, then deploy the policy to your target devices.

Ready to streamline your certificate rollouts?

Give your Mac fleet the frictionless security upgrade it deserves. For a deep dive into the technical prerequisites and a step-by-step configuration guide, check out our official documentation: Configure SCEP settings for macOS devices

Share

Nora Blake

I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.