
SCEPman is an Azure-native certificate authority (CA) and certificate lifecycle management (CLM) platform designed for environments where certificate failures have real production impact. It automates the full X.509 certificate lifecycle—issuance, renewal, validation, and revocation—across Intune- and Jamf-managed devices, on-prem and cloud servers, Linux systems, network infrastructure, and IoT devices using open PKI standards such as SCEP, Active Directory GPO, EST, OCSP, and CRL.
By replacing or consolidating legacy ADCS deployments, SCEPman removes the operational risk of manual certificate handling and parallel PKIs. Best practice defaults, object-bound certificates, and robust OCSP handling ensure predictable behavior under pressure. SCEPman runs entirely in your Azure tenant, giving you full sovereignty, auditability, and confidence in your operations.
Boring PKI. Reliable certificates.
Certificate Lifecycle Management That Prevents Outages
Secure Network Access Without Certificate Drama
First-Class Support for Intune and Jamf
Protect Servers and Non-MDM Systems
Phishing-Resistant Access for Privileged Users
Trust, Control, and Compliance—Without the Fear
Easy Azure Deployment via ARM Template or Terraform
RADIUSaaS Adds Network Enforcement
Trusted by Organizations Globally
Specifications
Certificates
- Device certificates (Wi-Fi, VPN, IoT)
- User certificates (identity, email)
- Server certificates (TLS/SSL)
- Code signing certificates (software, PowerShell scripts, Office macros)
- S/MIME certificates (email security)
- IoT certificates (secure endpoints)
- Active Directory Domain Controller certificates (WHFfB)
Protocols
- Enrollment: SCEP, Active Directory GPO, EST, REST API
- Validation: OCSP, CRL
Platforms & MDM
- MDM Solutions: Microsoft Intune, Jamf Pro, Kandji, Mosyle, Google Workspace, SOTI MobiControl
- Endpoints: Windows, macOS, iOS, Android, ChromeOS, Linux
- Server Platforms: Windows Server, Linux, various appliances
- Network Devices: Cisco & Meraki, HPE Aruba, Fortinet, Juniper, Ubiquiti, MikroTik, Sophos, Extreme Networks, and others
Deployment
- Deploy via Azure Marketplace, ARM (Azure Resource Manager) templates or Terraform
- PowerShell cmdlet for identity setup
- Root CA generation
Scalability
- 50 to 100,000+ users
- Geo-redundancy, auto-scaling
- Hierarchical CA topology (root and intermediate CA)
Administration & Security
- Hosted in your Azure tenant
- Azure Key Vault (HSM-backed, geo-redundancy)
- Real-time certificate revocation (object binding)
- Full manual control over certificates (issue, revoke)
- Automatic updates, patching
Full Service
- Incident support
- All updates included
Architecture
SCEPman is an Azure App deployed in your Azure tenant

















