
zt5qd (zt5qd) asked a question.
macOS Endpoints Became Unmanaged 1 Year After SCEP Deployment. To fix it and make a device managed again, I have to revoke the SCEP cert, and redeploy. Is this expected behavior? Shouldn't the SCEP cert automatically renew?

Hello Danny, Thank you for posting on our Community page!
This seems to be expected behaviour as per our doc:
"Okta as a CA doesn't support renewal requests. Instead, redistribute the profile before the certificate expires to replace the expired certificate. All MDM SCEP policies should be configured to allow for profile redistribution."
https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/configure-ca-main.htm
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.
Ask Us Anything about Workflows now thru 10/31