Richard M. Hicks Consulting, Inc.

Enterprise Mobility and Security Infrastructure | Microsoft Entra Private Access, Always On VPN and DirectAccess, Absolute Secure Access, Certificates and PKI
  • Consulting
  • Always On VPN Book
  • Entra Private Access
  • Entra Internet Access
  • PKI
  • PQC
  • IPv6
  • DPC
  • CertKit
  • Training
  • About Me
  • Contact
  • Microsoft MVP

    Microsoft Most Valuable Professional (MVP)

    Richard M. Hicks - Microsoft Most Valuable Professional (MVP)
    • X
    • LinkedIn
    • GitHub
    • YouTube
    • Facebook
    • Reddit
    • Discord
    • Patreon
  • Consulting

    Richard M. Hicks Consulting, Inc.
  • Pluralsight

    Video training courses on Pluralsight
  • Newsletter

    Richard M. Hicks Consulting, Inc. Enterprise Mobility Newsletter
    • 464XLAT
    • 6to4
    • AADJ
    • Absolute
    • Absolute Secure Access
    • Absolute Software
    • Active Directory
    • Active Directory Certificate Services
    • AD CS
    • ADC
    • ADCS
    • Admin Center
    • administration
    • Always On VPN
    • Always On VPN Book
    • Always On VPN DPC
    • AMA
    • Amazon EC2
    • Amazon Web Services
    • AOVPN
    • AOVPN Book
    • AovpnDPC
    • application delivery controller
    • Application Filter
    • authentication
    • Automation
    • Autopilot
    • AWS
    • Azure
    • Azure Active Directory
    • Azure AD
    • Azure AD Join
    • Azure App Proxy
    • Azure Application Gateway
    • Azure Application Proxy
    • Azure Conditional Access
    • Azure Load Balancer
    • Azure MF
    • Azure MFA
    • Azure Traffic Manager
    • Azure Virtual WAN
    • Azure VPN
    • Azure VPN Gateway
    • BIG-IP
    • BIND DNS
    • CBA
    • Certificate Authentication
    • Certificate Authority
    • Certificate Connector for Intune
    • Certificate Lifecycle Management
    • Certificate Services
    • Certificate-Based Authentication
    • certificates
    • CertKit
    • Cisco
    • Cisco Umbrella
    • Cisco Umbrella Roaming Client
    • Citrix ADC
    • CLAT
    • CLM
    • cloud
    • Cloud PKI
    • Cloud Service
    • Cloudflare
    • Community
    • Compliance
    • Conditional Access
    • Conference
    • Consulting Services
    • Cryptography
    • CVE
    • Deployment
    • Device Management
    • device tunnel
    • DHCP
    • DHCP Option 108
    • DirectAccess
    • DirectAccess Book
    • DirectAccess Deprecated
    • DirectAccess End of Life
    • DirectAccess EOL
    • Discord
    • DNS
    • DNS Policies
    • DNS Proxy
    • DNS64
    • DPC
    • DPC Support
    • Dynamic Host Configuration Protocol
    • Dynamic Profile Configurator
    • EAP
    • EAP-TLS
    • EC2
    • ECC
    • education
    • Elliptic Curve Cryptography
    • encapsulation
    • Encryption
    • end of life
    • Endpoint Manager
    • Enterprise
    • enterprise mobility
    • Entra
    • Entra App Proxy
    • Entra Application Proxy
    • Entra CBA
    • Entra Certificate-Based Authentication
    • Entra Conditional Access
    • Entra Global Secure Access
    • Entra ID
    • Entra Internet Access
    • Entra Private Access
    • Entra Private Network Connector
    • EOL
    • Event
    • extensible authentication protocol
    • F5
    • force tunnel
    • force tunneling
    • Forefront TMG 2010
    • Forefront UAG 2010
    • Forum
    • General
    • Geographic Redundnacy
    • GitHub
    • Global Secure Access
    • global server load balancer
    • Group Policy
    • GSA
    • GSLB
    • HAADJ
    • High Availability
    • Hotfix
    • Hybrid Azure AD Join
    • Hybrid Entra ID Join
    • Hybrid Entra Join
    • IKEv2
    • ILA
    • iManage
    • Important Links
    • Infrastructure
    • Intelligent Local Access
    • Intune
    • Intune Certificate Connector
    • Intune PFX Connector
    • IP-HTTPS
    • IPv6
    • IPv6 Transition
    • IPv6 Translation
    • ISATAP
    • KDC Proxy
    • Kemp
    • Kerberos
    • L2TP
    • learning
    • Linux
    • Load Balancing
    • LoadMaster
    • local traffic manager
    • LTM
    • Manage Out
    • MDM
    • MEM
    • MEMCM
    • MFA
    • Microsoft
    • Microsoft Endpoint Manager
    • Microsoft Entra
    • Microsoft Entra Global Secure Access
    • Microsoft Entra ID
    • Microsoft Entra Internet Access
    • Microsoft Entra Private Access
    • Microsoft Ignite
    • Microsoft Intune
    • migration
    • ML-DSA
    • ML-KEM
    • Mobile Device Management
    • Mobility
    • Multifactor Authentiction
    • multisite
    • MVP
    • NAC
    • Name Resolution
    • name resolution policy table
    • NAP
    • NAT64
    • NCA
    • NCSI
    • NDES
    • NetMotion
    • NetMotion Mobility
    • NetMotion Software
    • Netscaler
    • Network Access Control
    • network connectivity assistant
    • network connectivity status indicator
    • Network Device Enrollment Service
    • Network Device Enrollment Services
    • network policy server
    • nmap
    • NPS
    • NRPT
    • Offline Domain Join
    • OMA-DM
    • OMA-URI
    • Open Source
    • OpenDNS
    • OpenSSL
    • OpenVPN
    • Operational Support
    • Option 108
    • OTP
    • Patch Tuesday
    • PEAP
    • PFX Connector
    • PKCS
    • PKI
    • Pluralsight
    • PointSharp
    • Post-Quantum Cryptography
    • PowerShell
    • PowerShell 7
    • PPTP
    • PQC
    • Private Network Connector
    • Professional Services
    • ProfileXML
    • Protected EAP
    • Proxy
    • Proxy Server
    • public cloud
    • public key infrastructure
    • Quad9
    • Quantum Computing
    • Quantum Cryptography
    • RasMan
    • RCE
    • RDP
    • Recommended Reading
    • Reddit
    • Remote Access
    • Remote Administration
    • Remote Desktop Protocol
    • reporting
    • routing
    • routing and remote access service
    • RRAS
    • RSAT
    • SASE
    • SCCM
    • SCEP
    • Secure Access Service Edge
    • Secure Boot
    • Secure Service Edge
    • Secure Socket Tunneling Protocol
    • Secure Web Gateway
    • Security
    • Security Service Edge
    • Security Update
    • Server Core
    • Signature
    • Signing
    • Simple Certificate Enrollment Protocol
    • SMSS
    • Split DNS
    • split tunnel
    • split tunneling
    • SQL
    • SQL Server
    • SQL Server 2022
    • SQL Server Management Studio
    • SSE
    • SSL
    • SSL and TLS
    • SSMS
    • SSTP
    • Surface Pro
    • Surface Pro 4
    • SWG
    • System Center 2012
    • System Center Configuration Manager
    • systems management
    • Teredo
    • TLS
    • TLS 1.3
    • TND
    • TPM
    • Traffic Filter
    • Training
    • transition technology
    • Transport Layer Security
    • troubleshooting
    • Trusted Network Detection
    • Trusted Platform Module
    • UEFI
    • Uncategorized
    • Update
    • user tunnel
    • video
    • Visual Studio
    • Visual Studio Code
    • VPN
    • VPN Proxy
    • VS Code
    • Vulnerability
    • Web Application Proxy
    • Web Proxy
    • Web Proxy Server
    • webinar
    • WinCLAT
    • Windows 10
    • Windows 11
    • Windows 7
    • Windows 8
    • Windows 8.1
    • Windows Admin Center
    • Windows CLAT
    • Windows Server 2008 R2
    • Windows Server 2012
    • Windows Server 2012 R2
    • Windows Server 2016
    • Windows Server 2019
    • Windows Server 2022
    • Windows Server 2025
    • Workshop
    • WorkSite
    • XML
    • Zero Trust
    • Zero Trust Network Access
    • Zscaler
    • ZTNA

All posts tagged install

Microsoft Intune Certificate Connector Configuration Failed – String Cannot Be of Zero Length

When deploying on-premises enterprise PKI certificates using Microsoft Intune with Simple Certificate Enrollment Protocol (SCEP) certificate profiles, administrators must deploy a Windows Server with the Network Device Enrollment Service (NDES) role installed. Once configured, the Microsoft Intune Certificate Connector can be installed and configured to allow administrators to issue and manage certificates for their Intune-managed endpoints.

Configuration Failed

After configuring NDES, administrators may encounter an error message when installing the Microsoft Intune Certificate Connector. The message states:

Configuration Failed

Configuring Microsoft Intune Certificate Connector failed. No changes were made to Feature or Proxy settings. Please try again.

Unexpected Failure. Error: System.ArgumentException: String cannot be of zero length.
Parameter name: name
at System.Security. PrincipaI.NTAccount..ctor(String name)
at Microsoft.lntune.Connectors.ConfigUlScep.SetServiceUserPermissions(String username)
at Microsoft.lntune.Connectors.ConfigUlScep.SetNdesUserPermissions(String username)
at Microsoft.lntune.Connectors.ConfigUlScep.Enable()
at Microsoft.Intune.Connectors.ConfigUI.ApplyConfiguration.<ApplyChanges>d__10.MoveNext()

Missing Service Account

This error occurs because the administrator configured the NDES role using the default application pool identity, which the Intune Certificate connector does not support.

Resolution

To resolve this issue, configure the SCEP application pool to run as a Group Managed Service Account (gMSA), which is a security best practice. Alternatively, you can configure the SCEP application pool to run as a regular domain service account (not recommended).

SCEP Application Pool Configuration

To update the SCEP application pool to run as a gMSA or domain service account, add the service account to the IIS_IUSRS group. If running as a domain service account and not a gMSA, be sure to also grant the service account the Logon as a Service right.

Next, open Internet Information Services (IIS) Manager (inetmgr.exe) and follow the steps below.

  1. Expand the NDES server in the navigation tree.
  2. Highlight Application Pools.
  3. Right-click the SCEP application pool and choose Advanced Settings.
  4. In the Process Model section, highlight Identity.
  5. Click the ellipses next to ApplicationPoolIdentity.
  6. Select Custom account.
  7. Click Set.
  8. Enter the service account using the domain\username format. Be sure to include the trailing $ when specifying a gMSA.
  9. If using a standard domain service account, enter and confirm the password.
  10. Click Ok three times.
  11. Finally, stop and start the application pool for the changes to take effect.

Note: Using a gMSA requires additional configuration in the domain. Details here.

Once complete, be sure to assign the Request Certificates permission to the gMSA or domain service account on the issuing certification authority (CA) server. In addition, assign Enroll permission to the service account on the NDES certificate template in Active Directory (AD).

Intune Certificate Connector

The Intune Certificate Connector does not support running under a gMSA. However, when using NDES/SCEP, it’s acceptable to run the connector service under the SYSTEM account. Ensure the connector server’s computer account is granted Issue and Manage Certificates permissions on the issuing CA server.

Summary

For NDES used with Intune SCEP certificate profiles, a group Managed Service Account (gMSA) is the preferred service account. A standard domain user account is supported if a gMSA is not an option. Specify the account when you configure the NDES role or leave the default ApplicationPoolIdentity and replace it with the gMSA before installing the Intune Certificate Connector.

Additional Information

Microsoft NDES Information Disclosure: Detection and Remediation

Microsoft NDES Security Hardening: Protecting and Monitoring the SCEP Registry Configuration

Troubleshooting NDES Error 0x80070003 Path Not Found on Windows Server 2025

Troubleshooting NDES Error 0x80094800 Unsupported Cert Type on Windows Server 2025

Training: Mastering Enterprise PKI Certificates with Microsoft Intune

Share this:

  • Email a link to a friend (Opens in new window) Email
  • Print (Opens in new window) Print
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Pinterest (Opens in new window) Pinterest

Like this:

Like Loading…
Leave a comment
by Richard M. Hicks on October 6, 2026  •  Permalink
Posted in Active Directory Certificate Services, Certificate Connector for Intune, certificates, Intune, Intune Certificate Connector, Intune PFX Connector, Microsoft, Microsoft Intune, NDES, Network Device Enrollment Service, Network Device Enrollment Services, PFX Connector, SCEP, Simple Certificate Enrollment Protocol
Tagged configuration, enterprise, gMSA, Group Managed Service Account, install, installation, InTune, Intune certificate connector, Microsoft, Microsoft Intune, Mobility, NDES, Network Device Enrollment Service, path not found, SCEP, security, Simple Certificate Enrollment Protocol, warning, Windows

Posted by Richard M. Hicks on October 6, 2026

https://directaccess.richardhicks.com/2026/10/06/microsoft-intune-certificate-connector-configuration-failed-string-cannot-be-of-zero-length/

  • Always On VPN Book

    Always On VPN book available now on Amazon!
  • DirectAccess Book

    Order my DirectAccess book on Amazon now!
  • Masterclass

    Mastering Enterprise PKI Certificates with Microsoft Intune
  • Yubikey

    YubiKey FIDO Passkey
  • Recent Posts

    • Microsoft Intune Certificate Connector Configuration Failed – String Cannot Be of Zero Length
    • When Windows CLAT (WinCLAT) Is Used on IPv6-Mostly and IPv6-Only Networks
    • Microsoft Global Secure Access (GSA) Traffic Forwarding Profiles v2
    • How Windows CLAT (WinCLAT) Discovers the NAT64 Prefix
    • Microsoft Begins Rolling Out Windows CLAT (WinCLAT) for IPv6-Mostly and IPv6-Only Networks
  • Resources

    • 47-Day Public TLS Certificates
    • About Me
    • Absolute Secure Access
    • Absolute Secure Access Enterprise VPN
    • Absolute Secure Access Purpose-Built Enterprise VPN Advanced Features In Depth
    • Absolute Secure Access Zero Trust Network Access
    • Absolute Secure Access ZTNA
    • Always On VPN
    • Always On VPN and Multifactor Authentication
    • Always On VPN Book
    • Always On VPN DPC
    • Always On VPN DPC
    • Always On VPN DPC Advanced Features
    • Always On VPN DPC Commercial Support
    • Always On VPN DPC with Intune
    • Always On VPN Training
    • Always On VPN vs. Entra Private Access
    • CertKit
    • Choosing an Enterprise VPN
    • Citrix NetScaler ADC Load Balancing
    • Consulting
    • Consulting Services
    • Contact
    • Digital Certificates and TPM
    • Digital Certificates for Strong Authentication
    • DirectAccess
    • DirectAccess Consulting and Troubleshooting Services
    • DirectAccess Consulting Services
    • DirectAccess End of Life (EOL)
    • DirectAccess is now Always On VPN
    • DirectAccess Training
    • Drawbacks of Multifactor Authentication
    • Enterprise Mobility
    • Enterprise PKI
    • Enterprise VPN
    • Entra Global Secure Access
    • Entra Internet Access
    • Entra Private Access
    • F5-BIG-IP Load Balancing
    • How Do VPNs Protect You From Cyber Threats?
    • Implementing Always On VPN
    • Implementing DirectAccess with Windows Server 2016
    • Intune and Certificates Training
    • IPv6
    • Kemp LoadMaster Load Balancing
    • Microsoft Cloud PKI for Intune
    • Microsoft Entra Global Secure Access
    • Microsoft Entra Internet Access
    • Microsoft Entra Private Access
    • Multifactor Authentication (MFA)
    • NetMotion Mobility
    • NetMotion Mobility Enterprise VPN
    • NetMotion Mobility Purpose-Built Enterprise VPN
    • NetMotion Mobility Purpose-Built Enterprise VPN Advanced Features In Depth
    • Network Security and Virtual Private Networks (VPNs)
    • Newsletter
    • PKI
    • Post Quantum Cryptography in the Enterprise
    • Richard M. Hicks Consulting Named in Enterprise Networking Magazine’s Top 10 VPN Consulting Services for 2020
    • Secure Access Service Edge (SASE)
    • Secure Service Edge (SSE)
    • Secure Web Gateway
    • Security Service Edge (SSE)
    • SSE vs. SASE
    • Training
    • Virtual Private Network (VPN)
    • Virtual Private Networking (VPN) and the Cloud
    • What Is a Secure Web Gateway?
    • What is a VPN?
    • What Is Always On VPN
    • What's The Difference Between SSE and SASE?
    • Zero Trust
    • Zero Trust Network Access (ZTNA)
    • ZTNA
  • Always On VPN Resources

    • Always On VPN Advanced Features
    • Always On VPN Enhancements
    • Always On VPN Features
    • Always On VPN Remote Access
    • Always On VPN Technology Overview
    • Always On VPN Troubleshooting
    • Deploy Always On VPN
  • DirectAccess Resources

    • DirectAccess Book
    • DirectAccess Consulting Services
    • DirectAccess Kemp Load Balancer Deployment Guide
    • DirectAccess Mailing List
    • DirectAccess on Microsoft TechNet
    • DirectAccess Play-by-Play Video
    • DirectAccess Video Training
    • DirectAccess Videos on YouTube
    • Remote Access on Microsoft TechNet
  • Active Directory Active Directory Certificate Services ADC AD CS ADCS Always On VPN AOVPN application delivery controller authentication Azure CA certificate certificates Certification Authority cloud Cloud PKI configuration device tunnel DirectAccess DNS DPC education encryption endpoint manager enterprise mobility Entra Entra ID Entra Private Access error F5 firewall Global Secure Access group policy GSA high availability hotfix IKEv2 Important Links InTune IP-HTTPS IPsec IPv6 IPv6 transition technology Kemp learning load balancer load balancing management MDM MEM Microsoft Microsoft Endpoint Manager Microsoft Intune Mobility NDES Networking network policy server NPS performance PKCS PKI PowerShell ProfileXML public cloud public key infrastructure RAS redundancy Remote Access routing routing and remote access service RRAS SCCM SCEP security SSL SSTP TLS training troubleshooting update user tunnel VPN vulnerability warning webinar Windows Windows 7 Windows 8 Windows 10 Windows 11 Windows Server Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 XML Zero Trust Zero Trust Network Access ZTNA

Loading Comments...
%d