{{OnPremisesSecurityIdentifier}} strong certificate binding enforcement

Sebastian Cerazy 316 Reputation points
2025-02-26T10:00:30.62+00:00

We have this:

https://support.microsoft.com/en-gb/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16

Then we have this:

https://directaccess.richardhicks.com/2025/01/27/strong-certificate-mapping-enforcement-february-2025/

And also this:

https://learn.microsoft.com/en-us/mem/intune/protect/certificates-profile-scep

which states that {{OnPremisesSecurityIdentifier}} :

You can add the variable, formatted as {{OnPremisesSecurityIdentifier}}, to new and existing profiles in the Microsoft Intune admin center. This variable is supported in user certificates for macOS, iOS, and Windows 10/11, and only works with the URI attribute.

But I do NOT authenticate users access via USER certificate but MACHINE certificate

It seems that OnPremisesSecurityIdentifier is not added to the machine certificate (maybe because the machine does not fully exists in AD - I only have ghost objects to be used for Radius authentication)

So what is the deal with it? Another half-baked solution?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
2,011 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 52,321 Reputation points Microsoft Vendor
    2025-02-27T01:47:50.0166667+00:00

    @Sebastian Cerazy, Thanks for posting in Q&A. For device certificate, we can also add the variable, formatted as {{OnPremisesSecurityIdentifier}}, to new and existing profiles. You can see the information as below:

    User's image And yes, it is only supported in device certificates for Microsoft Entra hybrid joined devices and only works with the URI attribute. For other device types, the device certificates that authenticate with the KDC will be denied when it is fully enforced in Sept 2025 according to the above links. And user certificates should be used instead. For the device certificates that are not authenticated with the KDC, it will not affect, I think.

    Hope my above thoughts can give you some help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.