SAML
authentication isn’t supported for the Always-On connect method.
If you want to use certificate-based authentication, create a SCEP certificate
profile by following the steps below.
On the Microsoft Intune admin center, navigate to DevicesiOS/iPadOS devicesConfiguration.
Click CreateNew Policy.
Set the Profile type to Templates and select
SCEP Certificate as the template name.
Click Create.
Enter a name and description and click Next.
In the Configuration settings tab, select a type depending on how you plan to
use the certificate profile:
User: User certificates can contain both user and
device attributes in the subject and SAN of the certificate.
Device: Device certificates can only contain
device attributes in the subject and SAN of the
certificate.
Enter Subject alternative name attributes and values for
the profile. You can enter more than one subject alternative name. The text
value can contain variables and static text for the attributes.
Enter the Certificate validity period. Intune supports a
validity period of up to 24 months.
Select key usage options for the certificate:
Digital signature: Allow key exchange only when a
digital signature helps protect the key.
Key encipherment: Allow key exchange only when
the key is encrypted.
Select the number of bits contained in the key.
Select the trusted Root Certificate profile you
previously configured and assigned to applicable users and devices for this SCEP
certificate profile. The trusted certificate profile is used to provision users
and devices with the Trusted Root CA certificate.
Add Extended key usage values for the certificate's
intended purpose.