Site icon Richard M. Hicks Consulting, Inc.

Microsoft Intune Certificate Connector Configuration Failed – String Cannot Be of Zero Length

When deploying on-premises enterprise PKI certificates using Microsoft Intune with Simple Certificate Enrollment Protocol (SCEP) certificate profiles, administrators must deploy a Windows Server with the Network Device Enrollment Service (NDES) role installed. Once configured, the Microsoft Intune Certificate Connector can be installed and configured to allow administrators to issue and manage certificates for their Intune-managed endpoints.

Configuration Failed

After configuring NDES, administrators may encounter an error message when installing the Microsoft Intune Certificate Connector. The message states:

Configuration Failed

Configuring Microsoft Intune Certificate Connector failed. No changes were made to Feature or Proxy settings. Please try again.

Unexpected Failure. Error: System.ArgumentException: String cannot be of zero length.
Parameter name: name
at System.Security. PrincipaI.NTAccount..ctor(String name)
at Microsoft.lntune.Connectors.ConfigUlScep.SetServiceUserPermissions(String username)
at Microsoft.lntune.Connectors.ConfigUlScep.SetNdesUserPermissions(String username)
at Microsoft.lntune.Connectors.ConfigUlScep.Enable()
at Microsoft.Intune.Connectors.ConfigUI.ApplyConfiguration.<ApplyChanges>d__10.MoveNext()

Missing Service Account

This error occurs because the administrator configured the NDES role using the default application pool identity, which the Intune Certificate connector does not support.

Resolution

To resolve this issue, configure the SCEP application pool to run as a Group Managed Service Account (gMSA), which is a security best practice. Alternatively, you can configure the SCEP application pool to run as a regular domain service account (not recommended).

SCEP Application Pool Configuration

To update the SCEP application pool to run as a gMSA or domain service account, add the service account to the IIS_IUSRS group. If running as a domain service account and not a gMSA, be sure to also grant the service account the Logon as a Service right.

Next, open Internet Information Services (IIS) Manager (inetmgr.exe) and follow the steps below.

  1. Expand the NDES server in the navigation tree.
  2. Highlight Application Pools.
  3. Right-click the SCEP application pool and choose Advanced Settings.
  4. In the Process Model section, highlight Identity.
  5. Click the ellipses next to ApplicationPoolIdentity.
  6. Select Custom account.
  7. Click Set.
  8. Enter the service account using the domain\username format. Be sure to include the trailing $ when specifying a gMSA.
  9. If using a standard domain service account, enter and confirm the password.
  10. Click Ok three times.
  11. Finally, stop and start the application pool for the changes to take effect.

Note: Using a gMSA requires additional configuration in the domain. Details here.

Once complete, be sure to assign the Request Certificates permission to the gMSA or domain service account on the issuing certification authority (CA) server. In addition, assign Enroll permission to the service account on the NDES certificate template in Active Directory (AD).

Intune Certificate Connector

The Intune Certificate Connector does not support running under a gMSA. However, when using NDES/SCEP, it’s acceptable to run the connector service under the SYSTEM account. Ensure the connector server’s computer account is granted Issue and Manage Certificates permissions on the issuing CA server.

Summary

For NDES used with Intune SCEP certificate profiles, a group Managed Service Account (gMSA) is the preferred service account. A standard domain user account is supported if a gMSA is not an option. Specify the account when you configure the NDES role or leave the default ApplicationPoolIdentity and replace it with the gMSA before installing the Intune Certificate Connector.

Additional Information

Microsoft NDES Information Disclosure: Detection and Remediation

Microsoft NDES Security Hardening: Protecting and Monitoring the SCEP Registry Configuration

Troubleshooting NDES Error 0x80070003 Path Not Found on Windows Server 2025

Troubleshooting NDES Error 0x80094800 Unsupported Cert Type on Windows Server 2025

Training: Mastering Enterprise PKI Certificates with Microsoft Intune

Exit mobile version