Set up Device Trust with Microsoft Intune on iOS and iPadOS
Complete the Microsoft Intune setup before deploying these profiles.
Deploy the profiles
-
Create an iOS/iPadOS Trusted certificate policy named Firezone Root and upload the root CA certificate.
-
Create another iOS/iPadOS trusted certificate policy named Firezone Issuer and upload the issuing CA certificate.
-
Create an iOS/iPadOS SCEP certificate policy with certificate type Device. Enter the device identity certificate values, select Firezone Root as the root certificate, and enter your CA’s SCEP URI (Firezone Issuer if using Cloud PKI).
-
Create an iOS/iPadOS VPN policy. Select Custom VPN as the connection type and enter these values:
Setting Value Connection name FirezoneVPN server address 127.0.0.1Authentication method CertificatesAuthentication certificate The Firezone SCEP profile created in step 3 VPN identifier dev.firezone.firezone -
Add
accountSlugand any other managed configuration values as custom key-value pairs in the VPN profile. -
Assign the trusted certificate, SCEP, VPN, and Firezone app profiles to the same group. Sync a test iPhone or iPad and connect Firezone.
Settings supplied through a managed policy, including accountSlug, become
read-only in the Firezone Client. Users cannot change those values while the
policy is applied.
Verify access
Connect the test Client and open a Resource protected by Require attestation. Test again after renewing the certificate.
Need help? See all support options.