PKI Insights Webinar - Overcoming HSM Challenges with Enhanced Visibility - March 20th @ 10 AM - Register Today!
Schedule a Demo
Blog November 30, 2016 Authentication, Development, Enrollment, Internet of Things, NDES, NDES Policy Module, PKI, Policy Module, White Papers

Creating a NDES Policy Module – A Programmers Guide

by Mark B. Cooper

Microsoft introduced a great security improvement in Windows Server 2012 R2 to alter the standard Network Device Enrollment Service (NDES) security process. If you are familiar with the whitepaper I wrote for Microsoft (Securing and Hardening NDES) you’ll know I wrote about the disadvantages of using NDES for BYOD and Internet accessible enrollment solutions. The Microsoft InTune product team has been the only product so far to write a Policy Module that improves on the security and issuance model for NDES.

While Microsoft wrote the Policy Module capabilities with an open platform, to-date no other solutions have written a policy module. That is a real shame. Whether it’s a lack of information or visibility, I constantly work with my clients to make sure they are aware of how to secure NDES in their environments. If poorly deployed, it can present a significant thread gateway to your environment and a threat to your PKI.

Thankfully, Tochi Ezebube, an Engineer at Microsoft has written a paper on how to interface to, and write your own Policy Module. The paper is available here: https://msdnshared.blob.core.windows.net/wp-content/uploads/2016/11/How-to-write-an-NDES-policy-module.pdf

While it is geared to developers, it goes a long way to bring light to the process and will certainly be a help to anyone looking to create an improved authentication mechanism for NDES.

Person sitting at a laptop while viewing the PKI Spotlight Dashboard.

Expand Your PKI Visibility

Discover why seeing is securing with revolutionary PKI monitoring and alerting.

Learn More About PKI Spotlight®

Related Resources

  • Blog
    February 26, 2025

    PKI Insights Recap – Strengthening Security in Banking & Finance with PKI

    PKI, PKI Insights
  • Blog Graphic indicating ADCS Certificate Authority Renewal Error
    February 18, 2025

    Preparing for Microsoft’s Strong Certificate Mapping Enforcement – What You Need to Know

    PKI, PKI Spotlight, PowerShell
  • Blog
    January 30, 2025

    Don’t Believe the FUD – Microsoft PKI is Your Key to Crypto Agility

    ADCS, Microsoft, Microsoft ADCS, PKI

Mark B. Cooper

President & Founder at PKI Solutions, Leading PKI Cybersecurity Subject Matter Expert, Author, Speaker, Trainer, Microsoft Certified Master.

View All Posts by Mark B. Cooper

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *