Is It Possible to Distribute Client Certificates to iOS Devices Using GlobalProtect SCEP Without MDM?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Is It Possible to Distribute Client Certificates to iOS Devices Using GlobalProtect SCEP Without MDM?

L1 Bithead

 

I would like to ask whether it is possible to distribute a client certificate to an iOS device at the time of GlobalProtect authentication by using SCEP, without relying on any MDM solution.

My goal is to enable client certificate–based distribution and authentication for GlobalProtect on iOS, and I am currently exploring approaches that do not require MDM (such as Intune or Jamf).

I am referring to the following documentation:

Based on this, I would like to confirm the following:

  • Can GlobalProtect use SCEP to distribute (or provision) a client certificate to an iOS device during GlobalProtect authentication?
  • Is it technically possible for an iOS device to receive and store a client certificate via GlobalProtect SCEP without using MDM?
1 REPLY 1

L7 Applicator

@TechNardi -- We have iPads with GP installed on them with cert auth included as a part of the auth process and it's been our experience it's not possible.  It's an iOS(ism), how Apple is designed.  GP can't make device level changes like that.  Installing certs need to come through the managed OS like the JAMF tool.

  • 510 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!