This guide explains how to configure and install a Simple Certificate Enrollment Protocol (SCEP) profile from Okta onto Windows devices using Swif.ai.
Prerequisites
Access to the Okta Admin Console
Swif Admin access
A Windows device to enroll
1. Generate SCEP Details in Okta
Log in to your Okta Admin Console.
Navigate to Security → Device integrations.
Click Add platform.
Select Desktop (Windows and macOS only) and click Next.
On the Add Device management platform page:
Copy and save the generated Okta SCEP URL and Secret key.
Go to the Certificate Authority tab and download the certificate.
2. Prepare the Certificate for Swif
Encode the downloaded certificate file in base64 format.
You can use an online tool like
In the Swif Admin Console, create a new policy:
Choose Windows Certificate Install Policy. Learn more →
Paste the base64-encoded certificate into the required field.
Assign this policy to the target Windows device(s).
3. Create and Assign the SCEP Certificate Policy
In Swif, create a new Windows SCEP Certificate policy. Learn more →
Fill in the following fields:
Fill in the recommended settings
Server URL: Paste the Okta SCEP URL you copied earlier.
Challenge: Enter the Secret key from Okta.
CA Thumbprint: This is the fingerprint of the certificate you downloaded.
Assign the SCEP policy to the Windows device(s).
4. Verification
After the assignment, the Windows device should automatically receive and install the SCEP certificate profile.
You can verify installation by checking the device’s certificate store.
Additional Resources
If you encounter any issues, please contact your IT administrator or Swif support.













