Microsoft introduced significant changes to Active Directory Certificate Services (AD CS) certificate authentication with KB5014754. These changes enforce strong certificate mapping to address elevation of privilege vulnerabilities related to certificate spoofing. The changes affect organizations that use Microsoft AD CS for certificate-based authentication that relies on user attributes in certificates (for example, Wi-Fi or Ethernet with 802.1X).Documentation Index
Fetch the complete documentation index at: https://docs.iru.com/llms.txt
Use this file to discover all available pages before exploring further.
Enforcement Dates and Requirements
Review the following enforcement timeline and certificate requirements before you change Library Items or Connector versions.February 11, 2025
February 11, 2025
Strong certificate mapping enforcement began by default.
September 10, 2025
September 10, 2025
Compatibility mode is no longer supported.
Action required for certificates
Action required for certificates
All certificates used for Active Directory authentication must include the user’s security identifier (SID) in the Subject Alternative Name (SAN) field.
Who Needs to Take Action?
This applies to customers who use Microsoft AD CS for certificate-based authentication that relies on user attributes in certificates (for example, Wi-Fi or Ethernet with 802.1X).Prerequisites
Confirm the following before you update the AD CS Connector, SCIM, or Library Items for strong certificate mapping.User assignments in Iru Endpoint
User assignments in Iru Endpoint
Assign users to device records in Iru Endpoint before proceeding with certificate updates.
Connector host: OS, .NET, TPM, WebView, domain
Connector host: OS, .NET, TPM, WebView, domain
If you use the Iru Endpoint AD CS Connector for certificates issued from AD CS, install .NET 8 or later on the Windows Server 2019 or newer host that runs the Connector. The Connector host is often not the same machine as your AD CS Certification Authority (CA). For the full requirement list, including TPM or vTPM, see AD CS Connector Server Requirements in AD CS Connector Installation.
Required Steps
Update Iru Endpoint AD CS Connector
Strong certificate mapping requires the updated Iru Endpoint AD CS Connector at a supported 2.x version (see the prerequisites above). On Windows Server, download the latest Iru Endpoint AD CS Connector from Integrations > Active Directory Certificate Services (you can use Redownload Connector on the Connector card) and install it on the host. For upgrading an updated Connector on Iru Endpoint, see Updating the Iru AD CS Connector. For replacing the legacy Kandji Connector after tenant migration, see Migrating from Kandji to Iru with AD CS in AD CS Integration: Overview. When a new updated registration appears next to a legacy Connector row, complete Assign servers and remove the legacy entry as described in Migrating from Kandji to Iru with AD CS or Updating the Iru AD CS Connector. For install, sign-in, and registration URL flow, see Initialization in AD CS Connector Installation.Update SCIM User Directory Integration
Sign in to the Microsoft Entra admin center
Sign in to the Microsoft Entra admin center.
Add onPremisesSecurityIdentifier attribute
Add a new field:
onPremisesSecurityIdentifier (leave type as String).Configure mapping fields
Configure the mapping:
- Mapping type: Direct (default)
- Source attribute:
onPremisesSecurityIdentifier - Target attribute:
onPremisesSecurityIdentifier
Update Certificate Library Items
For SCEP Certificate Library Items
Open assigned SCEP Library Items
In Iru Endpoint, locate SCEP Library Items assigned in your Blueprints.
For Certificate Library Items using the AD CS Connector
Open assigned Certificate Library Items
In Iru Endpoint, locate and open Certificate Library Items assigned in your Blueprints.
For Wi-Fi or Ethernet Library Items using SCEP or AD CS certificates for EAP-TLS
Open assigned Wi-Fi or Ethernet Library Items
In Iru Endpoint, locate and open Wi-Fi or Ethernet Library Items assigned in your Blueprints.
Deployment and Certificate Reissuance
After updating Library Items:- Iru Endpoint automatically reissues certificates to devices assigned the updated Library Items through their Blueprints
- New certificates will contain the user’s SID in the SAN field, satisfying Microsoft’s strong certificate mapping requirements
- Any reconfigured Wi-Fi or Ethernet connections will automatically use the new certificates
Next Steps
After you save Library Item changes:Review the AD CS rollout order (optional)
See AD CS Integration: Overview for the AD CS setup path diagram and rollout order.
Considerations
Prevent network lockouts
Prevent network lockouts
Incorrectly updating certificates used for network connectivity can cause devices to disconnect from the network.
Validate in a test Blueprint first
Validate in a test Blueprint first
Test these changes on a subset of devices using a test Blueprint with test Library Items before applying changes to production Library Items.