This guide explains how to configure and install a Simple Certificate Enrollment Protocol (SCEP) profile from Okta onto Windows devices using Swif.ai.
Prerequisites
Access to the Okta Admin Console
Swif Admin access
A Windows device to enroll
1. Generate SCEP Details in Okta
Log in to your Okta Admin Console.
Navigate to Security → Device integrations.
Click Add platform.
Select Desktop (Windows and macOS only) and click Next.
On the Add Device management platform page:
Copy and save the generated Okta SCEP URL and Secret key.
Go to the Certificate Authority tab and download the certificate.
2. Prepare the Certificate for Swif
Encode the downloaded certificate file in base64 format.
You can use an online tool like
In the Swif Admin Console, create a new policy:
Assign this policy to the target Windows device(s).
3. Create and Assign the SCEP Policy
In Swif, create a new SCEP policy.
Fill in the following fields:
Fill in recommended settings
Server URL: Paste the Okta SCEP URL you copied earlier.
Challenge: Enter the Secret key from Okta.
CA Thumbprint: This is the fingerprint of the certificate you downloaded.
Assign the SCEP policy to the Windows device(s).
4. Verification
After the assignment, the Windows device should automatically receive and install the SCEP certificate profile.
You can verify installation by checking the device’s certificate store.
Additional Resources
If you encounter any issues, please contact your IT administrator or Swif support.