Skip to main content
Question

Is it acceptable to use 2 SAN Types for strong certificate mapping?

  • December 8, 2025
  • 2 replies
  • 35 views

bwoods
Forum|alt.badge.img+14

For strong certificate mapping, can two SAN types be used in the Subject Alternative Names field? Official guidance specifies using only the SCEP URI, and although the current configuration with multiple SAN types appears to work, it seems unreliable, as I’m seeing additional certificate-selection prompts. This change was made while I was out, so I need to confirm that this approach follows best practice.
 

 

2 replies

Forum|alt.badge.img+11
  • Valued Contributor
  • December 8, 2025

I think multiple values work.  In case you’re not just showing an example, double check the documentation to ensure the extension attribute value actually matches the numerical value of the EA.  Meaning, if the extension attribute is {jssURL}/view/settings/computer-management/computer-extension-attributes/46 that the tag:microsoft{EA}value ends in 46.  Also I believe the SAN type is Uniform Resource Identifier


  • Explorer
  • December 10, 2025

removed