I have been working on this for days now and still have not been able to make it work correctly. I have built a JAMF profile with payload for SCEP configuration. I have entered the URL, CA Name, Subject and Challenge type (Dynamic-Microsoft CA). I have also entered the correct admin page but when I import the profile to the Mac Device it never makes the challenge request. I see it go through GetCACaps, then GetCACert and finally it tried to make the PKIOperation request but since it never requested a challenge password this fails. I can make the profile work if I use static and manually pull down a challenge password but this isn't a good way to deploy Certificates in an Enterprise environment. I have also opened the .mobileconfig file with a text editor but I don't see the mscep_admin URL defined anywhere. Not sure if anyone has some tips or information that I might have missed that could help me out.
Question
Microsoft SCEP Challenge Request
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
