The following tasks must be completed before proceeding with the steps outlined in this documentation.

  • A certificate authority server must be set up and configured as described in Setting up a Microsoft CA for NDES/SCEP/MSCEP. The CA must be an Enterprise CA as opposed to a Stand Alone CA (Stand Alone does not allow for the configuration and customization of templates).
    • A Network Device Enrollment Service, also referred to as MSCEP server setup. NDES is only available in the Enterprise version of Microsoft Server 2008 and 2008 R2.
  • Microsoft Exchange with ActiveSync enabled.
  • Internet Information Services (IIS) on the EAS server must have the option “Client Certificate Mapping Authentication” installed.