Can I change a client's certificate mode after setup?
For a client set up recently the question does not arise: the wizard no longer asks, and every authority it creates issues both user and device certificates. There is nothing to change.
A client set up before that change may be on one kind only, and the wizard cannot widen it — the choice was offered when the authority was created and never again, which is exactly why it was removed. Which mode a client is on is shown beside its name on the client page, so the answer is at least visible.
If one of those needs widening, raise a ticket. It is safe: the same authority signs both kinds, so no certificate already issued is affected and no device has to re-enrol. What changes is that you are then offered a user profile as well as a device profile.
Related questions
- Why does every device need the Trusted Root CA installed?
- What is SCEP, and how does it work?
- Can I use Jamf, Mosyle, Kandji or another MDM instead of Intune?
- Device certificates or user certificates — what is the difference?
- Can I use Passbeam for a network with no Entra ID at all — printers, cameras, door access, building controls?
- How do I set up printers, CCTV, BMS and IoT devices that support 802.1X?
- What happens when a certificate is about to expire?
Still stuck? Ask us, or read the rest of the knowledge base.