Set up Device Trust with Microsoft Intune on Android

Complete the Microsoft Intune setup before deploying these profiles.

Corporate-owned and personally owned devices

On corporate-owned devices, your organization manages the device and grants Firezone access to the certificate through Intune. Android supplies a managed keychain alias without requiring a Firezone managed app configuration.

On personally owned devices, Intune manages a separate work profile. Deploy Firezone and its certificate in that profile, then require a device certificate with deviceCertificate=true. The user selects the certificate when prompted.

For personally owned work profiles, omit the firezone://serial/{{SerialNumber}} SAN from the shared certificate values. Keep firezone://intune-id/{{DeviceId}}. Android 12 and later restrict access to hardware serial numbers for these devices, which can cause certificate provisioning to fail.

Deploy the profiles

  1. Create Firezone Root and Firezone Issuer trusted certificate profiles for the Android Enterprise enrollment type you use, then upload the matching CA certificate to each profile.
  2. Create an Android Enterprise SCEP profile for that enrollment type. Enter the device identity certificate values, select Firezone Root as the root certificate, and enter your CA’s SCEP URI (Firezone Issuer if using Cloud PKI).
  3. Add Firezone from managed Google Play and assign it to the same profile and group as the SCEP profile.

Corporate-owned devices

  1. In the SCEP profile's Apps settings, configure Certificate access to grant access silently to specific apps, and select Firezone.
  2. Assign the SCEP profile and Firezone app to the same device group.

Personally owned devices

  1. Create a managed-device app configuration policy targeting Firezone.
  2. Set its profile type to Personally-Owned Work Profile Only.
  3. Add deviceCertificate with type Boolean and value true.
  4. Assign the policy, SCEP profile, and Firezone app to the same user group.
  5. Ask the user to open Firezone in the work profile and select the Firezone device certificate when Android prompts them.

Managed settings are read-only in the Firezone Client. With deviceCertificate=true, users must select a certificate and cannot turn off the certificate requirement.

Sync a test device, then open Settings → Device Trust in Firezone and confirm that the identity and private key are available. The certificate and Firezone app must be installed in the same Android profile.

Verify access

Connect the test Client and open a Resource protected by Require attestation. Test again after renewing the certificate. For corporate-owned devices, retain certificate access for Firezone during renewal. For personally owned devices, select the renewed identity if prompted.


Need help? See all support options.