Site icon Richard M. Hicks Consulting, Inc.

Certificate Connector for Intune Configuration Failure

Deploying user or device authentication certificates to support Always On VPN requires installing the Certificate Connector for Microsoft Intune. The same connector can link Intune to on-premises public key infrastructure (PKI) using PKCS or SCEP certificates. The connector can be configured to run in the SYSTEM context or a domain service account.

Configuration Failure

Administrators may encounter the following error message when installing the certificate connector and selecting the option to use a domain service account.

“Configuration failed. Configuring Microsoft Intune Certificate Connector failed. No changes were made to Feature or Proxy settings. Please try again.”

Root Cause

This error occurs because the service account does not have the correct permissions assigned on the server where the connector is being installed. Specifically, the service account must have the Logon as a service right assigned. To do this, open the local group policy editor (gpedit.msc) and perform the following steps.

  1. Expand Computer Configuration > Windows Settings > Security Settings > Local Policies > User Rights Assignment.
  2. Double-click Log on as a service.
  3. Click Add User or Group.
  4. Add the service account.
  5. Click OK.

Once complete, remove the Certificate Connector for Intune and re-run the installation again.

Additional Information

Always On VPN Windows 11 Issues with Intune

Always On VPN and Autopilot Hybrid Azure AD Join

Always On VPN Default Class-based Route and Intune

Exit mobile version