-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
- HP Community
- Poly Phones
- Desk and IP Conference Phones
- Re: Poly CCX400 and Intune PKCS

Create an account on the HP Community to personalize your profile and ask a question
08-04-2026 07:57 AM
We are currently trying to push PKCS certificates from Microsoft Intune to be used for network access control (802.1X). On the Intune side, the deployment status reports as completely successful, and we have already verified with Microsoft support that the Intune configuration and payload delivery are functioning correctly.
However, on the phone side, we are running into a dead end. There is no trace in the phone logs indicating that a certificate payload was received or processed. The local certificate store/options menu on the phone remains completely empty. Is there a known limitation or specific provisioning configuration required to bridge Intune-pushed certs into the Poly application layer (PVOS)? Or it is not possible to do that from Intune?
thanks
Solved! Go to Solution.
Accepted Solutions
08-07-2026 06:56 AM
Hello @RadeMal ,
Welcome to the HP Poly community.
This is just a Peer-to-peer community forum and not HP Poly Support.
We are all just Volunteers.
Configuration of certificates or similar is not an option that is available for the Poly CCX range via Intune.
You would need either a local server or our free option Poly Lens
The FAQ or a forum search has more answers.
Best Regards
Steffen Baier
Notice: I am an HP Poly employee but all replies within the community are done as a volunteer outside of my day role. This community forum is not an official HP Poly support resource, thus responses from HP Poly employees, partners, and customers alike are best-effort in attempts to share learned knowledge.
If you need immediate and/or official assistance for former Poly\Plantronics\Polycom please open a service ticket through your support channels
For HP products please check HP Support.
Please also ensure you always check the General VoIP , Video Endpoint , UC Platform (Microsoft) , PSTN
08-05-2026 02:13 PM
Hello @RadeMal, Welcome to the HP Poly Support Community.
Thank you for posting in the Poly Community and for providing a detailed overview of your environment and the troubleshooting already completed.
Based on your description, Microsoft has confirmed that the Intune PKCS certificate deployment is successful, but the Poly CCX 400 does not show any evidence that the certificate payload is being received or imported. Since the local certificate store on the phone remains empty and no certificate-related events appear in the device logs, additional validation is required on both the device provisioning and management sides.
Please review the following advanced troubleshooting steps:
1. Verify CCX Firmware Version
Ensure the CCX 400 is running the latest supported firmware version.
- Navigate to Settings > Status > Platform > Application
- Record the firmware version
- Compare it with the latest firmware available for the CCX platform
Certificate handling and device-management capabilities can vary between firmware releases.
2. Confirm Device Operating Mode
Please verify whether the phone is running in:
- Microsoft Teams Mode
- Open SIP Mode
The certificate provisioning workflow and supported management functions may differ depending on the operating mode.
3. Review Intune Certificate Profile Type
Confirm whether the certificate is being delivered using:
- PKCS certificate profile
- SCEP certificate profile
Also verify:
- Certificate template configuration
- Key usage settings
- Extended Key Usage (EKU) requirements for 802.1X authentication
- Certificate validity period
4. Force Device Synchronization
After confirming the policy assignment:
- Manually sync the device from Intune.
- Reboot the CCX 400.
- Allow sufficient time for policy processing.
- Review the phone logs immediately after synchronization.
5. Review Device Logs
Capture fresh logs following a policy sync and look for:
- MDM enrollment events
- Certificate import attempts
- Provisioning errors
- Authentication failures
- PVOS management messages
The absence of certificate-related log entries may indicate the payload is not being processed at the device layer.
6. Validate Other Intune Policies
Confirm whether other Intune-managed settings are successfully applied, such as:
- Device configuration profiles
- Compliance policies
- Teams-related settings
If other profiles are applying correctly while certificates are not, this helps isolate the issue to certificate provisioning.
7. Verify Certificate Store Visibility
On the CCX 400, check:
Settings > Security > Certificates (if available)
Confirm whether:
- The certificate store remains empty.
- Any root or intermediate certificates are present.
- The PKCS certificate appears after synchronization.
Could you please provide:
- The CCX 400 firmware version.
- Whether the phones are running Teams or Open SIP mode.
- Whether the profile is PKCS or SCEP.
- A device log collected immediately after a successful Intune synchronization.
This information will help determine whether the behavior is related to certificate delivery, device processing, or a platform limitation.
Have a great day!
I'm an HP Employee.
If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.
And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.
08-07-2026 05:00 AM
Hello @Meghana_10,
Firmware ver. 9.5.0.1321
Operating mode: MS Teams
PKCS Certificate profile
Certificate template:
client authentication, Subject name CN={{Device_Serial}}.XXXX.XXXX.Priv (our local domain)
Key usage: digital signature, Allow key exchange only with key encryption
EKU: Client auth, Server auth.
Cert. validity: 1 year
Currently can`t get logs from the phone as it doesn`t allow web connection, I tried to enable it with cfg file with these lines
httpd.cfg.enabled="1"
httpd.cfg.secureTunnelEnabled="0"
httpd.cfg.secureTunnelRequired="0"
httpd.enabled="1"
but it was unsuccessful.
Phone is online and signed in to Teams. Enrolled in Intune and all. It just doesn`t let me access it using web ui.
08-07-2026 06:14 AM
Thank you so much for the response @RadeMal
Since all the recommended troubleshooting has already been performed and the problem still persists, the next best step would be to contact our HP Support Team for further assistance. If your headset is still under warranty, they will be able to guide you through the warranty claim process and provide the appropriate support.
https://support.hp.com/us-en/poly
Take care and have an amazing day!
I'm an HP Employee.
If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.
And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.
08-07-2026 06:20 AM
Just need one more info. Does CCX400 supports PKCS certificates deployed through Intune, and whether there are any known limitations or validation steps for certificate-based authentication on the device?
Thank you!
08-07-2026 06:56 AM
Hello @RadeMal ,
Welcome to the HP Poly community.
This is just a Peer-to-peer community forum and not HP Poly Support.
We are all just Volunteers.
Configuration of certificates or similar is not an option that is available for the Poly CCX range via Intune.
You would need either a local server or our free option Poly Lens
The FAQ or a forum search has more answers.
Best Regards
Steffen Baier
Notice: I am an HP Poly employee but all replies within the community are done as a volunteer outside of my day role. This community forum is not an official HP Poly support resource, thus responses from HP Poly employees, partners, and customers alike are best-effort in attempts to share learned knowledge.
If you need immediate and/or official assistance for former Poly\Plantronics\Polycom please open a service ticket through your support channels
For HP products please check HP Support.
Please also ensure you always check the General VoIP , Video Endpoint , UC Platform (Microsoft) , PSTN