Set up Device Trust with Microsoft Intune on iOS and iPadOS

Complete the Microsoft Intune setup before deploying these profiles.

Deploy the profiles

  1. Create an iOS/iPadOS Trusted certificate policy named Firezone Root and upload the root CA certificate.

  2. Create another iOS/iPadOS trusted certificate policy named Firezone Issuer and upload the issuing CA certificate.

  3. Create an iOS/iPadOS SCEP certificate policy with certificate type Device. Enter the device identity certificate values, select Firezone Root as the root certificate, and enter your CA’s SCEP URI (Firezone Issuer if using Cloud PKI).

  4. Create an iOS/iPadOS VPN policy. Select Custom VPN as the connection type and enter these values:

    SettingValue
    Connection nameFirezone
    VPN server address127.0.0.1
    Authentication methodCertificates
    Authentication certificateThe Firezone SCEP profile created in step 3
    VPN identifierdev.firezone.firezone
  5. Add accountSlug and any other managed configuration values as custom key-value pairs in the VPN profile.

  6. Assign the trusted certificate, SCEP, VPN, and Firezone app profiles to the same group. Sync a test iPhone or iPad and connect Firezone.

Settings supplied through a managed policy, including accountSlug, become read-only in the Firezone Client. Users cannot change those values while the policy is applied.

Verify access

Connect the test Client and open a Resource protected by Require attestation. Test again after renewing the certificate.


Need help? See all support options.