Choose Your CA, Pick Your Server: Hexnode UEM Expands macOS SCEP ControlsSolved

Hexnode Expert
Discussion
1 week ago Jul 21, 2026

Deploying certificates to your Macs just got a whole lot simpler! Our updated macOS SCEP policy settings make it effortless to secure Wi-Fi, VPNs, and apps across your Mac fleet, regardless of your certificate provider or hosting environment.

What’s New?

We’ve added fine-grained environment controls inside the SCEP Policy workflow:

  • Certificate Authority (CA) Selection: You can now explicitly define your CA architecture. Choose dedicated support for Microsoft Active Directory Certificate Services (AD CS), or select Generic to instantly connect with any third-party, SCEP-compliant CA provider.
  • Server Type Configuration: Specify your hosting topology with dedicated options for On-prem (local infrastructure) or Cloud (cloud-hosted PKI) setups to optimize certificate request routing.

Key Benefits

  • Fits Any Environment: Works smoothly whether your servers are hosted locally on-premises or in the cloud.
  • Use Any Certificate Provider: Connect directly to Microsoft AD CS or any third-party provider supporting standard SCEP protocols.
  • Hands-Free Device Security: Automatically push certificates to your fleet so users can seamlessly connect to corporate Wi-Fi, VPNs, and apps—no manual setup needed.

Ready to streamline certificate rollouts across your Macs? Head over to Policies > macOS > Security > SCEP in your Hexnode UEM console and give your Mac fleet the frictionless security upgrade it deserves!

For more information, check out our help documentation on Configure SCEP settings for macOS devices.

Best Regards,
Isabel Lora
Hexnode UEM

Replies (0)

Be the first to reply!
Save