Skip to main content
Benjamin
Level 2.0: Eclair
June 16, 2026
Solved

Problem connecting a BYOD smartphone to a corporate Wi-Fi network with a certificate

  • June 16, 2026
  • 7 replies
  • 235 views
Hello,I'm trying to configure a corporate Wi-Fi network with certificate-based authentication.The connection works fine on an Android smartphone enrolled in Intune in COPE mode, but I can't get it to work on a smartphone enrolled in BYOD mode.I have a fleet of Samsung smartphones, both COPE and BYOD.The certificate is installed on the BYOD smartphones via an Intune PKCS profile, and I followed the recommendations (user-type certificate, Subject name = CN={{UserPrincipalName}}, and adding the SAN: User principal name (UPN) = {{UserPrincipalName}}, I published the CA that issued the certificate).The certificate is correctly installed on the BYOD smartphone and visible in the work profile, but the Wi-Fi connection fails.When I check the Wi-Fi configuration on the BYOD smartphone, there's no client certificate, which can explain the connection failure.Has anyone successfully configured a corporate Wi-Fi network with certificate authentication on a smartphone enrolled in BYOD mode on Intune?
Best answer by Benjamin

Hello,

Following the migration of BYOD enrollment to AMAPI on Intune, I can now select the user certificate when creating an Enterprise Wi-Fi configuration—something that wasn't possible with Intune Custom DPC enrollment. For now, I am conducting tests on a pre-production platform, so I cannot test the connection to the production Wi-Fi, but I believe the migration to AMAPI has resolved my issue.

7 replies

Kirk
Community Manager
June 16, 2026

Hi Benjamin, 

Welcome to the community!

It sounds like you’ve clearly already done the legwork here, the configuration sounds right (to my knowledge) and you've pinpointed exactly where it's breaking down.
 

One thing worth checking, if you haven't already: is the Wi-Fi profile in Intune directly referencing the PKCS certificate profile, rather than the certificate just being deployed separately? That's a step that's easy to miss and would explain why no client certificate is showing up in the Wi-Fi config.
 

That said, this does sound like it could be a known difference in how COPE and BYOD handle certain features in Android Enterprise, so if anyone in the community has hit this same wall and found a way through, we'd love to hear it.
 

Cheers,
Kirk

Benjamin
BenjaminAuthor
Level 2.0: Eclair
June 17, 2026

Hi Kirk, 

I have correctly configured the PKCS profile which installs the certificate in the Client Authentication setting of the Wifi profile.

Rakib
Level 3.0: Honeycomb
June 16, 2026

Remember you need two separate config profiles, one for BYOD and one for COPE. We have working wifi even for dedicated devices but are using device certificate.

Benjamin
BenjaminAuthor
Level 2.0: Eclair
June 17, 2026

Hi Rakib,

Indeed, in Intune, the profiles are different for BYOD and COPE, fully managed and dedicated.

I have created Wi-Fi, PKCS, and trusted certificate profiles for the BYOD devices.

Benjamin
BenjaminAuthor
Level 2.0: Eclair
August 3, 2026

Hello everyone,

I opened a support ticket with Microsoft, and since everything is correctly installed on the smartphone (certificates, Wi-Fi profile), they informed me that the issue does not stem from Intune.

However, I still cannot connect to the Wi-Fi.

So, I am asking again: has anyone successfully connected a BYOD-enrolled smartphone to a corporate Wi-Fi network using certificate-based authentication?

Thanks in advance for your replies.

Lizzie
Community Manager
August 4, 2026

Hey ​@Benjamin,

 

I hope you are doing well. 

 

I spoke with a colleague of mine in our engineering team last night about this. Would it be possible for you to send me privately via direct message with your Microsoft Intune Support ticket number please? We will see if we can dive a bit deeper into this one. 

 

Thanks,

Lizzie

Welcome to the Community everyone!
Benjamin
BenjaminAuthorAnswer
Level 2.0: Eclair
August 14, 2026

Hello,

Following the migration of BYOD enrollment to AMAPI on Intune, I can now select the user certificate when creating an Enterprise Wi-Fi configuration—something that wasn't possible with Intune Custom DPC enrollment. For now, I am conducting tests on a pre-production platform, so I cannot test the connection to the production Wi-Fi, but I believe the migration to AMAPI has resolved my issue.