{{OnPremisesSecurityIdentifier}} strong certificate binding enforcement

Sebastian Cerazy 351 Reputation points
2025-02-26T10:00:30.62+00:00

We have this:

https://support.microsoft.com/en-gb/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16

Then we have this:

https://directaccess.richardhicks.com/2025/01/27/strong-certificate-mapping-enforcement-february-2025/

And also this:

https://learn.microsoft.com/en-us/mem/intune/protect/certificates-profile-scep

which states that {{OnPremisesSecurityIdentifier}} :

You can add the variable, formatted as {{OnPremisesSecurityIdentifier}}, to new and existing profiles in the Microsoft Intune admin center. This variable is supported in user certificates for macOS, iOS, and Windows 10/11, and only works with the URI attribute.

But I do NOT authenticate users access via USER certificate but MACHINE certificate

It seems that OnPremisesSecurityIdentifier is not added to the machine certificate (maybe because the machine does not fully exists in AD - I only have ghost objects to be used for Radius authentication)

So what is the deal with it? Another half-baked solution?

Microsoft Security | Intune | Configuration

2 answers

Sort by: Newest
  1. Sebastian Cerazy 351 Reputation points
    2026-09-03T07:16:25.0633333+00:00

    Anybody could explain to me why this still works for me in 2026 (without any mappings) with exactly the same setup I always had?

    User’s laptops machine WiFi get on prem NPS authenticated with on prem Ent CA issued certificates via NDES Connector

    As stated above, not interested in user certificates for WiFi access

    Was this answer helpful?

    0 comments No comments

  2. Crystal-MSFT 54,326 Reputation points Microsoft External Staff
    2025-02-27T01:47:50.0166667+00:00

    @Sebastian Cerazy, Thanks for posting in Q&A. For device certificate, we can also add the variable, formatted as {{OnPremisesSecurityIdentifier}}, to new and existing profiles. You can see the information as below:

    User's image And yes, it is only supported in device certificates for Microsoft Entra hybrid joined devices and only works with the URI attribute. For other device types, the device certificates that authenticate with the KDC will be denied when it is fully enforced in Sept 2025 according to the above links. And user certificates should be used instead. For the device certificates that are not authenticated with the KDC, it will not affect, I think.

    Hope my above thoughts can give you some help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.