Set up Device Trust with Iru (Kandji) on Windows

Complete the Iru (Kandji) setup before deploying these profiles.

Use the shared certificate values for the subject, both URI SANs, key usage, and CA template. Deploy the public CA chain as described in the provider setup before issuing the identity.

Deploy the profiles

  1. In Iru Endpoint, go to Library → Add Library Item, search for SCEP, and give the item a descriptive name.

  2. Select Windows under Install on, choose the target Blueprints, and enter your SCEP server URL, challenge, and CA fingerprint.

  3. Set the subject to CN=dev.firezone.device-trust.

  4. Add these two URI Subject Alternative Name entries:

    firezone://kandji-id/$DEVICE_ID
    firezone://serial/$SERIAL_NUMBER
    

    The kandji-id claim name remains unchanged for compatibility with existing certificates and Firezone Clients.

  5. Select a 2048- or 4096-bit key and SHA-256 as the hash algorithm.

  6. Select Signing for Key Usage and add Client authentication as an Extended Key Usage.

  7. Disable private-key extraction and select the strongest key-protection option supported by your devices.

  8. Save the Library Item, allow a test Windows device to check in, and confirm the identity was installed in the local computer personal certificate store.

  9. Restart Firezone and open Settings → Device Trust to confirm that the certificate and private key are available.

Iru's SCEP Library Item supports static SCEP challenges and machine-level delivery on Windows.

Verify access and renewal

In Settings → Device Trust, confirm that both SANs contain the test device's inventory ID and serial number, with no unresolved profile variables.

Connect the test Client and open a Resource protected by Require attestation. Then enable Automatic profile redistribution in Iru and test a renewal before assigning the profile broadly. The replacement certificate must keep both the device ID and serial SANs.

Iru documents subject changes during automatic redistribution. Verify that the renewed certificate still has CN=dev.firezone.device-trust; Firezone uses this exact common name to select its identity. If your CA cannot preserve it, use a renewal workflow that does.


Need help? See all support options.