Windows Modern Device Certificates


You can install digital certificates to your devices using MobiControl profiles. You can upload certificates or generate new certificates based on Templates.

To set up certificate templates, refer to the Certificate Authorities page.

Add certificates to your devices using a Profile configuration. See Profiles for more general information on what Profiles are and how to push configurations to your devices. Once you have arrived at the Certificates dialog, use the steps below to install certificates on your devices.

You can add Client PFX or Root certificates to your devices. You can also configure devices to get certificates from a SCEP server.

Adding a Digital Certificate

Client PFX

Note: Client PFX certificates are only available on devices running Windows 10 or later. Any pfx certificates installed on older devices will be ignored.

  1. In the Add Profile dialog, click Add then Certificates to select Client PFX from the cascaded menu.
  2. Click New to add a new digital certificate.
  3. Click and navigate to the certificate file on your machine.
  4. Upload the certificate file to MobiControl.
  5. Enter the password if there is a password associated with the certificate file and then click OK.
  6. Repeat the previous steps to add multiple certificates.
  7. Click OK to return to the main Certificates dialog.
  8. On Windows Modern Desktop devices only: Specify if the certificate should be installed in the Device store or the User store.
  9. Click Ok to save your Certificates profile configuration.

Root

  1. In the Add Profile dialog, click Add then Certificates to select Root from the cascaded menu.
  2. Click New to add a new digital certificate.
  3. Click and navigate to the certificate file on your machine.
  4. Upload the certificate file to MobiControl.
  5. Repeat the previous steps to add multiple certificates.
  6. Click OK to return to the main Certificates dialog.
  7. On Windows Modern Desktop devices only: Specify if the certificate should be installed in the Device store or the User store.
  8. Specify the target location for the certificate installation from the following options:
    • Automatic
    • Trusted Root CA
    • Intermediate CA
    • Trusted Publishers
    • Trusted People

    Note: You cannot install certificates on the User store in the Trusted Root CA location.

Certificate location settings are only applicable to devices running Windows 10 and later. For devices with an older version of Windows, certificate locations are automatically determined based on the type of certificate selected, and the location settings are ignored.

Certificate Templates

Templates allow MobiControl to request certificates on behalf of a user or device and install them, allowing for dynamic certificates.

Certificate templates are configured in the Certificates Authorities section of MobiControl, available through the Servers tab. Follow the instructions at Certificate Authorities to add a Certificate Template.

Once you have configured a template, they will appear in the Certificates profile configuration dropdown. Click OK to save this configuration.

© SOTI Inc.
Contact us