Set up Device Trust with Microsoft Intune on Windows
Complete the Microsoft Intune setup before deploying these profiles.
Deploy the profiles
- Under Devices → Manage devices → Configuration, create a Trusted certificate policy for Windows named Firezone Root and upload the root CA certificate.
- Create another Windows trusted certificate policy named Firezone Issuer and upload the issuing CA certificate.
- Create a Windows SCEP certificate policy. Select Device as the certificate type, enter the device identity certificate values, select Firezone Root as the root certificate, and enter your CA’s SCEP URI (Firezone Issuer if using Cloud PKI).
- For Key storage provider, choose the TPM option appropriate for your fleet and disable private-key export.
- Assign all three profiles, sync a test device, and confirm that the identity
is installed in
LocalMachine\My. - Restart Firezone and open
Settings → Device Trust. Confirm that it shows the expected Intune device ID and access to the private key.
The Firezone tunnel service runs as LocalSystem. If the certificate is visible
but signing fails, verify that SYSTEM can use its CNG private key.
Verify access
Connect the test Client and open a Resource protected by Require
attestation. Test again after renewing the certificate.
When multiple valid certificates overlap, Firezone selects the one with the newest
NotBefore value.
Need help? See all support options.