Enforcement Dates and Requirements
Review the following enforcement timeline and certificate requirements before you change Library Items or Connector versions.February 11, 2025
February 11, 2025
September 10, 2025
September 10, 2025
Action required for certificates
Action required for certificates
Who Needs to Take Action?
This applies to customers who use Microsoft AD CS for certificate-based authentication that relies on user attributes in certificates (for example, Wi-Fi or Ethernet with 802.1X).Prerequisites
Confirm the following before you update the AD CS Connector, SCIM, or Library Items for strong certificate mapping.User assignments in Iru Endpoint
User assignments in Iru Endpoint
Connector host: OS, .NET, TPM, WebView, domain
Connector host: OS, .NET, TPM, WebView, domain
Required Steps
Update Iru Endpoint AD CS Connector
Strong certificate mapping requires the updated Iru Endpoint AD CS Connector at a supported 2.x version (see the prerequisites above). On Windows Server, download the latest Iru Endpoint AD CS Connector from Integrations > Active Directory Certificate Services (you can use Redownload Connector on the Connector card) and install it on the host. For upgrading an updated Connector on Iru Endpoint, see Updating the Iru AD CS Connector. For replacing the legacy Kandji Connector after tenant migration, see Migrating from Kandji to Iru with AD CS in AD CS Integration: Overview. When a new updated registration appears next to a legacy Connector row, complete Assign servers and remove the legacy entry as described in Migrating from Kandji to Iru with AD CS or Updating the Iru AD CS Connector. For install, sign-in, and registration URL flow, see Initialization in AD CS Connector Installation.Update SCIM User Directory Integration
Sign in to the Microsoft Entra admin center
Open Entra ID
Open Enterprise applications
Open your SCIM app
Open provisioning settings
Open attribute mapping
Select Entra users mapping
Show advanced options
Edit attribute list
Add onPremisesSecurityIdentifier attribute
onPremisesSecurityIdentifier (leave type as String).Save attribute list
Start new mapping
Configure mapping fields
- Mapping type: Direct (default)
- Source attribute:
onPremisesSecurityIdentifier - Target attribute:
onPremisesSecurityIdentifier
Save mapping
Update Certificate Library Items
For SCEP Certificate Library Items
Open assigned SCEP Library Items
Edit the Library Item
Add SAN value
Select URI SAN type
Enter strong mapping value
$ADCS_STRONG_MAPPING_ID.Save changes
For Certificate Library Items using the AD CS Connector
Open assigned Certificate Library Items
Edit the Library Item
Add SAN value
Select URI SAN type
Enter strong mapping value
$ADCS_STRONG_MAPPING_ID.Save changes
For Wi-Fi or Ethernet Library Items using SCEP or AD CS certificates for EAP-TLS
Open assigned Wi-Fi or Ethernet Library Items
Edit the Library Item
Open Identity Certificate settings
Add SAN value
Select URI SAN type
Enter strong mapping value
$ADCS_STRONG_MAPPING_ID.Save changes
Deployment and Certificate Reissuance
After updating Library Items:- Iru Endpoint automatically reissues certificates to devices assigned the updated Library Items through their Blueprints
- New certificates will contain the user’s SID in the SAN field, satisfying Microsoft’s strong certificate mapping requirements
- Any reconfigured Wi-Fi or Ethernet connections will automatically use the new certificates
Next Steps
After you save Library Item changes:Validate on test devices
Review the AD CS rollout order (optional)
Considerations
Prevent network lockouts
Prevent network lockouts
Validate in a test Blueprint first
Validate in a test Blueprint first