In the 'Create a SCEP Certificte Profile' section (typo in the heading & URL BTW), there's no step for configuring the Subject Alternative Name, yet in the picture on Step 14 it looks like this has been selected as 'User principal name (UPN)'. Can you please confirm if this step has been missed from the current instructions?
This section could also do with a re-do to align the ordering of the various settings with how they appear in the current Intune portal (Certificate validity period and KSP have been pushed down the page somewhat) and needs a step added for configuring Certificate type (either User or Device). Thanks!
⚠Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.
@officedocsbot add label security
@officedocsbot assign @mypil
@officedocsbot add label security
@SteveBurkettNZ - Thank you for submitting feedback.
I will get this issue over to the Win10 ITPro writing team for investigation.
Thank you for reporting and making the docs better. Much appreciated.
I made a note to request the team to update this when the work is complete.
Will be interesting to see if any changes to the English version of this page could alleviate the translation bug in the Japanese version of the page, where 2 occurrences of a double asterisk ( * * ) contains a space between them, making it look like a broken MarkDown bold formatting issue (#3453).
@SteveBurkettNZ : This topic is not at all within my working experience, so I hope you will be able to help me out by confirming a couple of minor details from this page.
When looking at the lines containing a double asterisk in 2 different sections, are these asterisks actually part of the needed input/code/explanation/description here? Or can they be removed?
Relevant excerpts from the page. Notice in particular step 3 in the first section and step 15 in the second section:
The easiest way to verify the onPremisesDistingushedNamne attribute is synchronized is to use Azure AD Graph Explorer.

... skipping down to the next section containing an unverified double asterisk ...
Sign-in a workstation with access equivalent to a _domain user_.


The SCEP Certificate blade should open. Configure Certificate validity period to match your organization.
[!IMPORTANT]
Remember that you need to configure your certificate authority to allow Microsoft Intune to configure certificate validity.
Select Enroll to Windows Hello for Business, otherwise fail (Windows 10 and later) from the Key storage provider (KSP) list.

It's broken markdown.
If you check out the raw MD page and do a search for 'strong' you'll find:
type https://graph.windows.net/myorganization/users/[userid], where **[userid]
... I'd delete the strong and /strong tags and add a double asterisk at the end to get:
type https://graph.windows.net/myorganization/users/[userid], where [userid]
and the other is:
under Name. Type **1.3.6.1.4.1.311.20.2.2
… I'd delete the strong and /strong tags, add double asterisk either side of Name, add another double asterisk at the end to get:
under Name. Type 1.3.6.1.4.1.311.20.2.2
Thank you very much for the feedback regarding this somewhat unrelated issue.
I hope the other tech writers with experience in this topic will be able to help you.
@SteveBurkettNZ - From our understanding, the issue has been resolved based on the merged commit [0a62027] but it may take a few days for the merged content to appear in the article. If you feel it hasn't been resolved, please re-open this issue.
Thank you for your contribution to make the docs better! Much appreciated!
@officedocsbot close
Most helpful comment
It's broken markdown.
If you check out the raw MD page and do a search for 'strong' you'll find:
... I'd delete the strong and /strong tags and add a double asterisk at the end to get:
and the other is:
… I'd delete the strong and /strong tags, add double asterisk either side of Name, add another double asterisk at the end to get: