Endpoint management
Microsoft Intune

Install and bind the certificate on the NDES Server

5min

This section explores the following tasks:

  • Install the NDES certificate.
  • Bind the NDES certificate in IIS.
  • Configure request filtering.
  • Bind the certificate in the registry.

Install the NDES certificate

1

On the NDES server, open the Windows search bar and look for certlm.msc. Open it.

2

In the left toolbar, right-click Personal and select All Tasks > Request New Certificate.

3

On the Select Certificate Enrollment Policy page, select [ Active Directory Enrollment Policy ]. Select [ Next ].

4

Select the NDES certificate created earlier and select [ More information is required to enroll for this certificate. Click here to configure Settings ].

5

On the Certificate Properties page, make the following changes:

  1. For Subject Name, select [ Common Name ] and enter the Fully Qualified Domain Name of your NDES server. Then, select [ Add ].
  2. For Alternate Name, select [ DNS ] and enter the Fully Qualified Domain Name of your NDES server. Then, select [ Add ].
6

Select [ Apply ] and then [ OK ]. Then select [ Enroll ].

Bind the NDES certificate in IIS

1

On the NDES server, open the Windows search bar and look for Internet Information Services (IIS) Manager. Open it.

2

Expand your Server Name > Sites and then select [ Default Web Site ].

3

On the right side of the screen, locate Edit Site and select [ Bindings ].

4

On the Site Bindings page, select [ Add ].

5

Change the Type to HTTPS and select [ Select ]. Select the NDES certificate you just installed and select [ OK ].

Configure request filtering in IIS

1

On the NDES server, open the Windows search bar and look for Internet Information Services (IIS) Manager. Open it.

2

Expand your Server Name > Sites and then select [ Default Web Site ].

3

Locate and select [ Request Filtering ].

4

On the right side of the screen, locate and select [ Edit Feature Settings ].

5

Change the Max Url length and Max query string values to 65534. Select [ OK ].

Bind the certificate in the registry

1

On the NDES server, open the Windows search bar and look for System Registry Editor. Open it.

2

Navigate to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MSCEP and locate GeneralPurposeTemplate.

3

Change the value to the name of your certificate template created for NDES. (Not the display name.)

4

Close the registry editor and restart the NDES server.

For more information on configuring infrastructure for Intune, refer to the Microsoft documentation.