Set up Device Trust with Iru (Kandji) on Windows
Complete the Iru (Kandji) setup before deploying these profiles.
Use the shared certificate values for the subject, both URI SANs, key usage, and CA template. Deploy the public CA chain as described in the provider setup before issuing the identity.
Deploy the profiles
-
In Iru Endpoint, go to Library → Add Library Item, search for SCEP, and give the item a descriptive name.
-
Select Windows under Install on, choose the target Blueprints, and enter your SCEP server URL, challenge, and CA fingerprint.
-
Set the subject to
CN=dev.firezone.device-trust. -
Add these two URI Subject Alternative Name entries:
firezone://kandji-id/$DEVICE_ID firezone://serial/$SERIAL_NUMBERThe
kandji-idclaim name remains unchanged for compatibility with existing certificates and Firezone Clients. -
Select a 2048- or 4096-bit key and SHA-256 as the hash algorithm.
-
Select Signing for Key Usage and add Client authentication as an Extended Key Usage.
-
Disable private-key extraction and select the strongest key-protection option supported by your devices.
-
Save the Library Item, allow a test Windows device to check in, and confirm the identity was installed in the local computer personal certificate store.
-
Restart Firezone and open
Settings → Device Trustto confirm that the certificate and private key are available.
Iru's SCEP Library Item supports static SCEP challenges and machine-level delivery on Windows.
Verify access and renewal
In Settings → Device Trust, confirm that both SANs contain the test device's inventory ID and serial number, with no unresolved profile variables.
Connect the test Client and open a Resource protected by Require attestation. Then enable Automatic profile redistribution in Iru and test a renewal before assigning the profile broadly. The replacement certificate must keep both the device ID and serial SANs.
Iru documents subject changes during automatic redistribution. Verify that
the renewed certificate still has CN=dev.firezone.device-trust; Firezone
uses this exact common name to select its identity. If your CA cannot preserve
it, use a renewal workflow that does.
Need help? See all support options.