
SCEPman is a cloud-based public key infrastructure (PKI) that automates the entire X.509 certificate lifecycle for clients, servers, and IoT devices via the SCEP protocol. Seamlessly integrating with MDM platforms such as Intune and Jamf Pro , it provides automatic issuance, renewal, and revocation of certificates using the SCEP protocol.
Its object binding feature links certificates to users or machines, revoking them in real-time when needed, minimizing administrative tasks. SCEPman also supports TLS/SSL certificates for server authentication and integrates with RADIUSaaS for secure network access . Fully hosted in your Azure tenant, it ensures data sovereignty, automatic updates, and geo-redundancy for enhanced security.
What can we do for you?
Automate the Entire X.509 Certificate Lifecycle
Maintain Full Sovereignty With Zero-Trust Architecture
Protect Servers With Automated TLS/SSL Certificates
Sign Code, Emails, and Documents With Trusted Identities
Strengthen Security With Phishing-Resistant Access Control
Deployment and Premium Support Included
SCEPman + RADIUSaaS = Seamless & Secure Network Access
Let Our Customers Do the Talking
Specifications
Certificates
- Device certificates (Wi-Fi, VPN, IoT)
- User certificates (identity, email)
- Code signing certificates (software, PowerShell scripts, Office macros)
- S/MIME certificates (email security)
- Server certificates (TLS/SSL)
- IoT certificates (secure endpoints)
- Active Directory Domain Controller certificates (WHFfB)
Protocols
- Enrollment: SCEP, REST API, EST
- Validation: OCSP, CRL
Platforms & MDM
- MDM Solutions: Intune, Jamf Pro, Kandji, Mosyle, Google Workspace, SOTI MobiControl
- Platforms: Windows, macOS, iOS, Android, ChromeOS, Linux
- Server Platforms: Windows Server, Linux, various appliances
Deployment
- Deploy via Azure Marketplace, ARM (Azure Resource Manager) templates or Terraform
- PowerShell cmdlet for identity setup
- Root CA generation
Scalability
- 50 to 100,000+ users
- Geo-redundancy, auto-scaling
- Hierarchical CA topology
Administration & Security
- Hosted in your Azure tenant
- Azure Key Vault (HSM-backed, geo-redundancy)
- Real-time certificate revocation (object binding)
- Full manual control over certificates (issue, revoke)
- Automatic updates, patching
Full Service
- Incident support
- All updates included
Architecture
SCEPman is an Azure App deployed in your Azure tenant