Hello Mayer,
This seems familiar to me, I remember facing this issue quite a long time ago, maybe my experience can be helpful this time.
Well, in a standard NDES deployment, the challenge password is one-time/dynamic by design: NDES generates it through https://<NDES>/certsrv/mscep_admin, and the device subsequently submits that challenge to /certsrv/mscep; this is the model Microsoft uses for Intune SCEP.
For static/shared challenge passwords, this is not simply a supported NDES registry switch; the standard NDES workflow is based on generated enrollment passwords, while a policy module can provide dynamically generated, request-specific challenges and validate them against the device/certificate request. If the affected devices report “invalid SCEP challenge password,” first verify that the MDM is obtaining the challenge from /certsrv/mscep_admin and that the exact challenge is passed unchanged to the device; then check NDES/policy-module logs because an expired or mismatched challenge will be rejected.
If this is Microsoft Intune + NDES, I would not attempt to force a static password; instead, verify the Intune SCEP profile, Certificate Connector/NDES policy module, NDES URL, and the NDES service account/RA certificates. Microsoft specifically documents the policy module as the component that generates and validates the challenge password for mobile-device enrollment.
Let me know if there's anything missing, I'll try to work it out with you~
Xuan Nhu.