<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta SCEP Certificate Enrollment Fails on Windows Devices with a Non-Printable Character Error

Devices and Mobility
Okta Identity Engine

Overview

When an administrator distributes a Simple Certificate Enrollment Protocol (SCEP) certificate profile to Windows devices for device management attestation via a Mobile Device Management (MDM) provider, client certificate enrollment fails because Okta generates a secret key containing unsupported special characters. Regenerate the SCEP secret key in the Okta Admin Console using only supported alphanumeric characters and update the MDM profile to resolve the issue. During the failure, the Windows certificate store does not receive the management attestation certificate, the device fails to register as Managed in Okta, and the Windows Event Viewer logs the following error:

 

Error

 

SCEP: Certificate enroll failed. Result: (The string contains a non-printable character.)

 

Applies To

  • Okta Identity Engine (OIE)
  • Device Trust / Managed Devices (Okta FastPass)
  • Windows 10 / Windows 11
  • Okta as a Certificate Authority (CA)
  • Simple Certificate Enrollment Protocol (SCEP) Certificate Profile Deployment via Mobile Device Management (MDM)

Cause

The Windows `ClientCertificateInstall/SCEP` Configuration Service Provider (CSP) enforces strict character validation on the SCEP challenge password or secret key. If Okta generates a secret key containing certain symbols or characters, such as underscores (`_`), hyphens (`-`), or other special punctuation characters, the Windows SCEP CSP interprets them as non-printable or malformed characters and rejects the enrollment request before contacting or completing negotiation with the Certificate Authority (CA).

Solution

How does an administrator regenerate the SCEP secret key in Okta?

 

Regenerate the secret key in the Okta Admin Console to ensure it consists of standard alphanumeric characters.

  1. In the Okta Admin Console, navigate to Security > Device Integrations.
  2. Select the Endpoint management tab.
  3. Locate the platform configuration for the Windows deployment.
  4. Select the Actions dropdown menu next to the platform and choose Reset secret key.
  5. Copy the newly generated Secret Key and ensure it consists of standard alphanumeric characters without unsupported special characters.
  6. Select Save.

How does an administrator update the MDM SCEP profile?

 

Update the existing Windows SCEP configuration profile in the MDM administrative portal with the newly generated secret key.

  1. Sign in to the MDM administrative portal.
  2. Open the existing Windows SCEP configuration profile or CA credential template.
  3. Replace the existing challenge password or secret key with the newly copied secret key from Okta.
  4. Save and publish the updated profile to the targeted device groups.

How does an administrator verify the enrollment?

 

Force a device sync on a target Windows device and confirm the certificate issuance and managed status in the Okta Admin Console.

  1. On a target Windows device, force a device sync with the MDM.
  2. Open the Certificate Manager (certmgr.msc for Current User or certlm.msc for Local Machine, depending on the deployment store).
  3. Verify that the Okta management attestation certificate appears under Personal > Certificates.
  4. In the Okta Admin Console, navigate to Reports > System Log and confirm that Okta evaluates subsequent sign-in attempts from the device as Managed.
Loading
Okta SCEP Certificate Enrollment Fails on Windows Devices with a Non-Printable Character Error | Okta Support