The following error occurred while using the delegated Simple Certificate Enrollment Protocol (SCEP) to issue a client certificate:
Insufficient privileges to complete the operation.
- Okta Identity Engine (OIE)
- Microsoft Endpoint Manager
- Azure Active Directory
The underlying reason was the application permissions in Azure Active Directory.
Set the Intune scep_challenge_provider permissions:
-
Select Azure Active Directory > App registrations.
-
Click + Add a permission.
-
In the Request API permissions section, scroll down and then click Intune.
-
Under What type of permissions does your application require?, click on Application permissions.
-
In the Select permissions search field, enter scep, and then select the scep_challenge_provider checkbox.
-
Click Add permissions.
-
In the Configured permissions section, click ✔ Grant admin consent for <Tenant_Name>.
-
Click Yes in the message that appears.
