Set up Device Trust with Microsoft Intune on Android
Complete the Microsoft Intune setup before deploying these profiles.
Corporate-owned and personally owned devices
On corporate-owned devices, your organization manages the device and grants Firezone access to the certificate through Intune. Android supplies a managed keychain alias without requiring a Firezone managed app configuration.
On personally owned devices, Intune manages a separate work profile. Deploy
Firezone and its certificate in that profile, then require a device certificate
with deviceCertificate=true. The user selects the certificate when prompted.
For personally owned work profiles, omit the
firezone://serial/{{SerialNumber}} SAN from the shared certificate values.
Keep firezone://intune-id/{{DeviceId}}. Android 12 and later restrict access
to hardware serial numbers for these devices, which can cause certificate
provisioning to fail.
Deploy the profiles
- Create Firezone Root and Firezone Issuer trusted certificate profiles for the Android Enterprise enrollment type you use, then upload the matching CA certificate to each profile.
- Create an Android Enterprise SCEP profile for that enrollment type. Enter the device identity certificate values, select Firezone Root as the root certificate, and enter your CA’s SCEP URI (Firezone Issuer if using Cloud PKI).
- Add Firezone from managed Google Play and assign it to the same profile and group as the SCEP profile.
Corporate-owned devices
- In the SCEP profile's Apps settings, configure Certificate access to grant access silently to specific apps, and select Firezone.
- Assign the SCEP profile and Firezone app to the same device group.
Personally owned devices
- Create a managed-device app configuration policy targeting Firezone.
- Set its profile type to Personally-Owned Work Profile Only.
- Add
deviceCertificatewith type Boolean and valuetrue. - Assign the policy, SCEP profile, and Firezone app to the same user group.
- Ask the user to open Firezone in the work profile and select the Firezone device certificate when Android prompts them.
Managed settings are read-only in the Firezone Client. With
deviceCertificate=true, users must select a certificate and cannot turn off
the certificate requirement.
Sync a test device, then open Settings → Device Trust in Firezone and confirm that the identity and private key are available. The certificate and Firezone app must be installed in the same Android profile.
Verify access
Connect the test Client and open a Resource protected by Require attestation. Test again after renewing the certificate. For corporate-owned devices, retain certificate access for Firezone during renewal. For personally owned devices, select the renewed identity if prompted.
Need help? See all support options.