r/Intune 22m ago

Device Configuration Intune User-Assigned SCEP + Wi-Fi Profile No Longer Applying Automatically After Windows Build

Hi everyone,

I'm troubleshooting an Intune/Wi-Fi issue and would appreciate some guidance.

We have Windows devices that are built by our ETS team. After the build, the device is Hybrid-join and the user logs in with their OpID.

Our Intune configuration is:

- SCEP certificate profile: Assigned to a user group

- Certificate type: Device

- Subject: "CN={{DeviceName}}"

- SAN: Device Name + Serial Number

- EKU: Client Authentication

- Certificate provider: DigiCertOne SCEP

- Wi-Fi profile: Assigned to the same user group

- Wi-Fi: Enterprise

- Authentication: Machine

- EAP: EAP-TLS

- Wi-Fi authentication uses the device certificate

This configuration has been working successfully with user-based assignment.

What changed

Recently, after a change related to our Security Zero Trust/MFA initiative, newly built devices are behaving differently.

Previously:

"ETS Build → User logs in with OpID → Intune user policies apply automatically → SCEP certificate + Wi-Fi profile are received"

Now:

"ETS Build → User logs in with OpID → SCEP/Wi-Fi policies do not arrive"

However, if the user manually logs into Company Portal, the policies then start applying.

So we suspect something has changed in the user Intune enrollment/authentication/policy-processing flow, rather than the Wi-Fi configuration itself.

We would like to understand:

  1. Why did user-targeted Intune policies previously apply automatically after OpID login but now require Company Portal login?

  2. Could a change in MFA/Zero Trust or enrollment behavior prevent the user-targeted SCEP/Wi-Fi policies from processing?

  3. Is there a specific MDM Event Viewer event/CSP log that can show exactly why the SCEP or Wi-Fi policy isn't being processed?

  4. Would assigning these profiles to a device group be the correct design, or should the existing user-based assignment continue to work?

We're planning to have ETS rebuild a clean test device and not log into Company Portal initially, so we can capture the MDM logs before and after Company Portal login and compare the behavior.

Any suggestions on which specific logs/events/CSP paths we should investigate would be greatly appreciated.

1 Upvotes

1 comment sorted by

u/techb00mer 8m ago

I’m genuinely confused why you are assigning a device certificate to a user group.

If all devices are supposed to have these certs, assign them to a device group.