Fully managed Cloud PKI for Intune. Certificate-based Wi-Fi in minutes — no servers, no NDES.
Cloud PKI for Microsoft Intune — without the complexity
Set up secure, certificate-based Wi-Fi for Microsoft Intune in minutes.
No PKI infrastructure. No servers. No NDES. No scripts.
What you get
- Issue certificates in minutes, not days
- Eliminate manual PKI setup and ongoing maintenance
- Reduce risk with automated renewal and secure defaults
- Fully managed SaaS — nothing runs in your environment
- Works with Microsoft Intune and other SCEP-compatible MDMs
- Built for lean IT teams with limited time and resources
What EasyScep does
EasyScep is a fully managed Cloud PKI for Microsoft Intune that automates the entire certificate lifecycle — issuance, renewal, and revocation.
It removes the complexity of traditional PKI. No Windows Server CA, no NDES connectors, no certificate templates, no renewal scripts.
Most customers have never run a PKI before. EasyScep makes certificate-based authentication achievable from day one — securing Wi-Fi (EAP-TLS), and also supporting wired 802.1X and VPN.
When to use EasyScep
- You want certificate-based Wi-Fi (EAP-TLS) for Intune-managed devices
- You've never run a PKI and don't want to start now
- You want to reduce certificate-related outages and support overhead
- You run a mixed MDM environment (e.g. Intune and JAMF)
- You need a faster, simpler alternative to traditional PKI
- You're moving off an aging on-prem CA
How it works
- Subscribe on Microsoft Marketplace and connect EasyScep to Microsoft Entra ID (formerly Azure AD)
- Configure a SCEP profile in Intune — EasyScep provides the endpoint and trusted root
- Devices enroll automatically and renew certificates without manual intervention
Key capabilities
Automated certificate lifecycle
Issue, renew, and revoke certificates without manual processes.
Zero infrastructure
Fully managed SaaS — no servers, no NDES, no PKI expertise needed.
Microsoft-native integration
Works with Microsoft Intune and Microsoft Entra ID.
Multi-MDM support
Compatible with any MDM that supports SCEP with a shared secret, including JAMF and Workspace ONE.
Secure by default
Certificate-based authentication removes the risks of password-based access.
Works across environments
Supports Windows, macOS, iOS, Android, and mixed setups.
Why EasyScep vs traditional PKI
Traditional PKI: Complex setup that can take days or weeks.
EasyScep: Up and running in minutes.
Traditional PKI: Requires servers and ongoing maintenance.
EasyScep: Fully managed SaaS.
Traditional PKI: Relies on manual renewal processes.
EasyScep: Automates the certificate lifecycle.
Traditional PKI: Requires PKI expertise to manage reliably.
EasyScep: Designed for IT teams that need simplicity and speed.
Set up without disruption
EasyScep works with your existing Intune and Microsoft Entra ID setup.
No infrastructure changes. No migration project. No ongoing maintenance overhead.
Reduce risk without adding complexity
Avoid certificate outages, eliminate manual renewal errors, and ensure only trusted devices can access your network — automatically.
Built for Microsoft environments
EasyScep is a fully managed SaaS Cloud PKI that connects securely to your Microsoft environment through authorized APIs. Nothing runs in your tenant, and there's nothing to patch or maintain.
Pair with EasyRadius
Combine EasyScep with EasyRadius to enable full certificate-based network authentication for Wi-Fi, wired 802.1X, and VPN — with no on-prem infrastructure.
Get started on Microsoft Marketplace
Subscribe to a fully managed, cloud-native Cloud PKI that works right out of the box. Most environments go from subscription to issuing certificates within an hour.
Related Products
See also our EasyRadius offering for quick setup of RADIUS-based 802.1X and WPA-Enterprise authentication.
Learn more
Check out our documentation here.
Contact Us
Reach us at sales@just-software.com if you have any questions.