After you update to Microsoft System Center Configuration Manager current branch, version 1806 or 1810, the Microsoft Intune connector certificate renewal process fails.
This problem affects customers who have a hybrid mobile device management environment through Microsoft Intune. The problem occurs when the Service Connection Point is installed on a computer that is running Windows Server 2012 or Windows Server 2012 R2.
Additionally, error messages that resemble the following are recorded in the the DMPUploader log:
Exception: [Unable to cast COM object of type 'System.__ComObject' to interface type 'CERTENROLLLib.CX509PrivateKey'. This operation failed because the QueryInterface call on the COM component for the interface with IID '{728AB362-217D-11DA-B2A4-000E7BBB2B09}' failed due to the following error: No such interface supported (Exception from HRESULT: 0x80004002 (E_NOINTERFACE)).]
The renewal process starts at the halfway point of the certificate lifespan. If the renewal fails after the certificate is expired, Configuration Manager cannot connect to Microsoft Intune.
The following log entry in DMPUploader.log indicates a successful renewal:
Connector certificate renewed.
The following entry indicates a certificate that is already expired:
Making Web Request to Location Service Url exception System.Net.WebException: The remote server returned an error: (403) Forbidden.~~
at System.Net.HttpWebRequest.GetResponse()~~
at Microsoft.ConfigurationManager.DmpConnector.Connector.SccmProxyGenerator.GetRestUserAuthLocationServiceResponse()
To prevent this problem, apply this update. Certificates that are already expired have to be renewed manually to reestablish the Microsoft Intune connection.
For an expired certificate, use either of the following options.
-
Option 1
Migrate from a hybrid environment to Intune Standalone. Note that policies have to be re-created within seven (7) days in Intune Standalone to prevent the loss of policies and settings. For more information, see Migrate hybrid MDM users and devices to Intune standalone. -
Option 2
Contact Microsoft Customer Support Services for help to renew the certificate. For more information, see How to get support for Microsoft Intune.