As you may already know, you are able with Intune to provide a PKCS certificate for user when connecting to WiFi or VPN networks (see https://docs.microsoft.com/en-us/intune/protect/certficates-pfx-configure#create-a-pkcs-certificate-profile for more details).
If you wanted to use a PKCS certificate for device based authentication, this was only possible for macOS based devices.
Well, good news, the latest update of Intune (service release 1912) now offers this capability (device-based certificate) for all operating system (Windows, Android for Work and iOS; off course macOS is still supported)
When creating or editing the SCEP certificate profile type, you now have the choice for these OSes to choose between user or device