After registering an application for the CEG Service, you must add the following API permissions to the application.
| API Permission category | Permissions | 
|---|---|
| Intune | scep_challenge_provider (SCEP challenge validation) | 
| Microsoft Graph | Application.Read.All (Read all applications) | 
You must also grant administrative consent for these permissions to the application.
To add required API permissions to the CEG Service application
- Log in to the Microsoft Azure portal.
- Under Azure services, click Azure Active Directory.
- Click App Registrations.
- Select the application you created earlier for the CEG Service.
- Click API permissions.
- To add the required Intune API permissions:- Click Add a permission. The Request API permissions page appears.
- Click Microsoft APIs.
- Click Intune.
- Select Application permissions.
- Select the following Intune application permissions:- Select scep_challenge_provider (SCEP challenge validation). 
 
- Click Add permissions.
 
- To add the required Microsoft Graph API permissions:- Click Add a permission. The Request API permissions page appears.
- Click Microsoft APIs.
- Click Microsoft Graph.
- Select Application permissions.
- Select the following permissions:- Select Application.Read.All (Read all applications).
 
- Click Add permissions.
 
- When prompted, click Yes to confirm consent.