Enabling PKI Enrollment with Centrify User Suite. Using Centrify User Suite Microsoft Certificate Services

Similar documents
Creating and Issuing the Workstation Authentication Certificate Template on the Certification Authority

Exchange 2010 PKI Configuration Guide

Certificate Management

SQL Server Setup for Assistant/Pro applications Compliance Information Systems

Windows XP Exchange Client Installation Instructions

User Guide for eduroam

Thank you for using Synapse Hosted Exchange service. Please find the instructions for setting up your clients are below:

Professional Mailbox Software Setup Guide

Microsoft OCS with IPC-R: SIP (M)TLS Trunking. directpacket Product Supplement

Certificate Management

Use the below instructions to configure your wireless settings to connect to the secure wireless network using Microsoft Windows Vista/7.

AVG Business SSO Connecting to Active Directory

WatchDox SharePoint Beta Guide. Application Version 1.0.0

Installing Samsung SDS CellWe EMM cloud connectors and administrator consoles

Microsoft IAS Configuration for RADIUS Authorization

Technical Certificates Overview

Windows Firewall Configuration with Group Policy for SyAM System Client Installation

Centrify Cloud Connector Deployment Guide

Outlook Profile Setup Guide Exchange 2010 Quick Start and Detailed Instructions

UNI - WINDOWS. How to... Access your University on your Windows Computer. Introduction. Step 1/1 - Setting Up Your Windows Computer

Copyright

Installation Guides - Information required for connection to the Goldfields Institute s (GIT) Wireless Network

How to set up Outlook Anywhere on your home system

Configuring Thunderbird for Flinders Mail at home.

Meeting CJIS Advanced Authentication

Outlook Web App (Online)... 3 Outlook 2013 (Desktop) Apple Mail Mobile Devices Android iphone... 40

Installation Guide. . All right reserved. For more information about Specops Inventory and other Specops products, visit

MaaS360 Cloud Extender

Wireless Network Configuration Guide

Deployment of Keepit for Windows

Step-by-step installation guide for monitoring untrusted servers using Operations Manager ( Part 3 of 3)

Setup Guide. network support pc repairs web design graphic design Internet services spam filtering hosting sales programming

Professional Mailbox Software Setup Guide

MaaS360 On-Premises Cloud Extender

Updated: 7/10/2013 Author: Tim Unten

Installing Logos SSL Certificates on Mobile Devices

How to Set Up Outlook 2007 and Outlook 2010 for Hosted Microsoft Exchange if the Program is Already Installed

Rockets Smartphone Configuration. Spring 2012 Edition

Specops Command. Installation Guide

How to install and use the File Sharing Outlook Plugin

Username: Password: your password. Domain Name: EXCH026. Server Name: EAST.EXCH026.serverdata.net

Q. I use a MAC How do I change my password so I can send and receive my ?

Cloud Services ADM. Agent Deployment Guide

Cloud Attached Storage

Using Exclaimer Signature Manager with Office 365

PRODUCT WHITE PAPER LABEL ARCHIVE. Adding and Configuring Active Directory Users in LABEL ARCHIVE

Biznet GIO Cloud Connecting VM via Windows Remote Desktop

Hosted Microsoft Exchange Client Setup & Guide Book

Fus - Exchange ControlPanel Admin Guide Feb V1.0. Exchange ControlPanel Administration Guide

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

Toll Free: International:

Configuration of Microsoft Time Server

Security Assertion Markup Language (SAML) Site Manager Setup

Differences between Computer and User Templates

Upgrading User-ID. Tech Note PAN-OS , Palo Alto Networks, Inc.

Patriots Outlook Configuration

Hosted Microsoft Exchange 2013 Service. Getting Started Guide

Apple Mail Outlook Web Access (OWA) Logging In Changing Passwords Mobile Devices Blackberry...

How to configure your mobile devices post migrating to Microsoft Office 365

Setting Up Peak Performance Group Policies

BlackBerry Enterprise Service 10. Universal Device Service Version: Administration Guide

Symantec Managed PKI. Integration Guide for ActiveSync

USER GUIDE PowerAttachment CRM

Exchange ActiveSync (EAS)

5. For Display name, Your Full Name or the name you want to appear in the from box when writing or responding to click Next

Telstra Mobile Device Management (T MDM) Getting Started Guide

Instructions for Microsoft Outlook 2003

Exchange Outlook Profile/POP/IMAP/SMTP Setup Guide

6. After connecting reopen the wireless connections window. Right click on RamNet and select properties. Page 2 of 7

Configuring Outlook Express

Basic Exchange Setup Guide

Exchange Outlook Profile/POP/IMAP/SMTP Setup Guide

EventTracker: Support to Non English Systems

BlackBerry Universal Device Service. Demo Access. AUTHOR: System4u

Windows Server Update Services 3.0 SP2 Step By Step Guide

Configuring Color Access on the WorkCentre 7120 Using Microsoft Active Directory Customer Tip

How to Access Coast Wi-Fi

Faculty & Staff: Office 365 Migration

Creating a User Profile for Outlook 2013

MelbourneOnline Hosted Exchange Setup

NAS 206 Using NAS with Windows Active Directory

Using etoken for Securing s Using Outlook and Outlook Express

Getting Started Guide

CLEO NED Active Directory Integration. Version 1.2.0

Knights Outlook Configuration

APNS Certificate generating and installation

pcanywhere Advanced Configuration Guide

Hosted Microsoft Exchange Client Setup & Guide Book

HOW TO SILENTLY INSTALL CLOUD LINK REMOTELY WITHOUT SUPERVISION

Administration Guide. BlackBerry Enterprise Service 12. Version 12.0

Application Note. ShoreTel 9: Active Directory Integration. Integration checklist. AN June 2009

Exchange 2013 mailbox setup guide

Centrify DirectManage: Group Policy Management

Authentication in XenMobile 8.6 with a Focus on Client Certificate Authentication

setup information for most domains hosted with InfoRailway.

Internet Explorer 7 for Windows XP: Obtaining MIT Certificates

1 Outlook Web Access. 1.1 Outlook Web Access (OWA) Foundation IT Written approximately Dec 2010

EIOBoard Integration with Outlook and Exchange

Office 365 deploym. ployment checklists. Chapter 27

Transcription:

Enabling PKI Enrollment with Centrify User Suite With Centrify User Suite you can enable mobile devices to request a certificate for PKI authentication for either WiFi networks, and/or Exchange ActiveSync. The certificates are requested from your existing CA attached to your Active Directory, and can be used on both ios and (supported) Android Devices. Why should organizations use PKI based authentication? Using certificates for authentication is much more secure than the standard username and password scheme. Users must have the proper certificate installed on the device in order to access corporate services such as WiFi and Exchange Active Sync. These certificates are stored in very secure keyrings on the device, and in many cases stored in a hardware secured device that thwarts tampering or removing the certificates without proper approval. Another advantage of using certificates is that the user no longer needs to remember and enter a password to access corporate services requiring PKI based authentication. Better security, and better user experience. Using Centrify User Suite Microsoft Certificate Services Set-up CA server for auto-enrollment The following steps assume you have a working certificate services role/service within your domain. If you do not, please follow the article for setting up a CA. http://technet.microsoft.com/enus/library/cc772393(v=ws.10).aspx This document will describe creating 2 certificates for use in device enrollment. A User certificate for Exchange/SMIME use, and a Computer certificate for device authentication into WiFi networks. Configuration: Active Directory Configuration In Active Directory Group Policy Management snap-in, Right click Default Domain Policy Select Edit to open the Group Policy Management Editor In the Group Policy Management Editor snap-in, go to User Configuration container Expand Policies Expand Windows Settings Expand Security Settings

Select Public Key Policy On the right pane, double click on Certificate Services Client Certificate Enrollment Change the policy to Enabled. Keep others as default, click OK to save it. Do the same for Computer Configuration policy. Windows Server CA Configuration In Certification Authority snap-in, Right click Certificate Templates Select Manage In Certificate Templates Console snap-in, Right click on User template Select Duplicate Template Choose Windows Server 2003 Enterprise and click OK In Template display name In General tab, fill in the information as follows Template Name: User-ClientAuth In Security tab, make sure Domain Users has the Enroll permissions set. In the Subject Name tab, click the Supply in the request radio button.

Duplicate the Computer certificate template, and name it Computer-ClientAuth, and set the same settings as above. In Certification Authority snap-in, Select Certificate Templates Right-click and select New->Certificate Template to Issue

Select the newly created User-ClientAuth template and click OK Do the same for the Comptuer-ClientAuth template Centrify Cloud Proxy Configuration Open the Centrify Cloud Proxy Configuration tool, and select the Mobile Settings Tab Make sure the appropriate CA is selected for the configuration as completed above

User and Computer certificates are now configured for deployment to mobile devices, and can be used for further policy involving Microsoft ActiveSync and/or WiFi profiles. If a policy is created that requires the use of certificates, the devices will automatically request and enroll certificates. You can then go back to the Certificate Authority tool, and check to make sure certificates are generated for mobile devices, under Issued Certificates. See the Centrify documentation for configuration guides for PKI authentication for ActiveSync and WiFI.