Deployment Guide - Certificate Enrollment Infrastructure for BigFix MCM

This document provides guidance for deploying the certificate enrollment infrastructure required for BigFix Mobile Configuration Management (MCM). It describes how to integrate BigFix MCM with Microsoft certificate services to enable device certificate enrollment using the Simple Certificate Enrollment Protocol (SCEP).

The guide covers the configuration and integration of the following infrastructure components:

  • Microsoft Active Directory (AD) for directory services and identity management
  • Microsoft Certificate Authority (CA) for issuing device certificates
  • Network Device Enrollment Service (NDES) for providing the SCEP interface
  • NDES Proxy for securely forwarding certificate enrollment requests from BigFix to NDES
  • LDAP Proxy for enabling directory queries to Active Directory
  • BigFix MCM configuration, including SCEP profile setup in the BigFix user interface

This document also includes the deployment architecture, network communication flow, and required configuration steps to set up the certificate enrollment infrastructure and integrate it with BigFix MCM.

The guide is intended for deployment engineers, system administrators, and L2 support engineers responsible for configuring and maintaining the certificate infrastructure used for device certificate enrollment in BigFix MCM environments.