SCEP relies on shared challenge passwords that are easily intercepted from MDMs or disgruntled staff. Once leaked, any rogue device can request a trusted certificate, leaving you unable to distinguish a corporate laptop from a hacker s virtual machine.
SCEP allows private keys to be generated in software, meaning they can be exported, cloned, and moved to unauthorized hardware. A single stolen SCEP-issued certificate opens your entire enterprise security perimeter to persistent, untraceable access.
SCEP lacks any mechanism to verify the TPM or Secure Enclave, simply assuming the device is legitimate. In an era of sophisticated device spoofing, this lack of hardware attestation is a guaranteed recipe for a major breach.
ACME Device Attestation addresses all these problems by offering a password-less device identity-aware network access with hardware-rooted security. Security is no longer based on what you know (the passwords) but what you own (the company approved device/hardware).