Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

Create PKCS, Root CA, and Customer Root Certificate using Intune (MDM)

To configure the Skyhigh Client app using MDM, you must deploy the required certificates and policies from Intune to the managed device. Follow the steps below to create and push the certificates:

  1. Create Root CA Certificate as a Trusted Certificate
  2. Create PKCS Certificate
  3. Create Customer Root CA Certificate
Create Root CA Certificate as a Trusted Certificate 

NOTE: Generate and download the Root CA certificate from Active Directory, and then upload the certificate (generated from AD or the XEA tool) to the customer tenant in the SSE Web.

To upload the Root CA to Inune and deploy it to the device: 

  1. In Microsoft Intune, go to Device > Android > Configuration.
  2. Under Policies, click Create and select New Policy

    1.jpg
    Create a profile panel opens. 
  3. On the Create a profile panel, configure the following:
    • Platform. Select Android Enterprise as the platform for the profile. 
    • Profile type. Select Templates as the profile type.
      and select Trusted certificate as the Template name.
    • Click Create.

      2.jpg
      Trusted certificate window opens. 
       
  4. Under the Basics tab, enter a Name and Description, and click Next.

    3.png
  5. Under the Configuration settings tab, select the root CA downloaded from AD in the certificate file section and click Next.

    4.png
     
  6. Under the Assignments tab, add the required device or user group in the Included groups setting and click Next.

    5.png
     
  7. Under the Review + create tab, review the trusted certificate summary and click Create.

    6.png

    A trusted certificate is created and automatically pushed to the assigned device.
Create PKCS Certificate 

To create a PKCS certificate and deploy it to the device: 

  1. In Microsoft Intune, go to Device > Android > Configuration.
  2. Under Policies, click Create and select New Policy

    1.jpg
    Create a profile panel opens. 
     
  3. On the Create a profile panel, configure the following:
    • Platform. Select Android Enterprise as the platform for the profile. 
    • Profile type. Select Templates as the profile type.
      and select the PKCS certificate as the Template name.
    • Click Create.

      9.png
      PKCS certificate window opens. 
       
  4. Under the Basics tab, enter a Name and Description, and click Next.

    Screenshot (93).png
  5. Under the Configuration settings tab, enter the details from the Active Directory and upload the server Root Certificate

    Screenshot (96).png
     
  6. Under the Assignments tab, add the required device or user group in the Included groups setting and click Next.

    Screenshot (97).png
  7. Under the Review + create tab, review the PKCS certificate summary and click Create.

    Screenshot (98)_1.png

    A PKCS trusted certificate is created and automatically pushed to the assigned device.
     
Create the Customer Root CA Certificate

To create the customer Root CA certificate and deploy it to the device: 

  1. Download the scanning certificate from the customer tenant. 
  2. In Microsoft Intune, go to Device > Android > Configuration. 
  3. Under Policies, click Create and select New Policy

    1.jpg
    Create a profile panel opens. 
  4. On the Create a profile panel, configure the following:
    • Platform. Select Android Enterprise as the platform for the profile. 
    • Profile type. Select Templates as the profile type.
      and select Trusted certificate as the Template name.
    • Click Create.

      2.jpg
      Trusted certificate window opens. 
  5. Under the Basics tab, enter a Name and Description, and click Next.

    3.png

     
  6. Under the Configuration settings tab, rename the file extension from .pem to .cer, and then select the scanning certificate downloaded from the customer tenant.

    4.png
  7. Under the Assignments tab, add the required device or user group in the Included groups setting and click Next.

    5.png
     
  8. Under the Review + create tab, review the PKCS certificate summary and click Create.

    6.png
    A Root CA certificate is created and automatically pushed to the assigned device.

Once the certificates are installed or pushed to the device, install the Skyhigh Client app from the Google Play Store. For more information, see Skyhigh Client App for Android Devices. 

NOTE: To configure Disconnect VPN, Factory Reset, and Minimal OPG access for Android devices using MDM, see Disconnect VPN, Factory Reset, and Minimal OPG access

  • Was this article helpful?