Event banner
AMA: Microsoft Cloud PKI in Intune Suite
Event Ended
Wednesday, Mar 20, 2024, 10:30 AM PDTEvent details
Can you really simplify certificate management and move it to the cloud? Let’s get into it! This Ask Microsoft Anything (AMA) session is dedicated to the recently launched Microsoft Cloud PKI in the ...
Char_Cheesman
Updated Dec 27, 2024
Sal_INC2
Mar 20, 2024Occasional Reader
A few questions, that probably be on the mind of some: does it support an externally created, offline root CA? does it support custom EKUs? does it support custom templates? how does security works for enrollment, how do we limit who can request what certificates? what methods and protocols does it support for enrollment other than SCEP? can we issue certificates with custom properties similar to ADCS’ “supply in the request”, and how is that secured?
- EricTedjMar 20, 2024
Microsoft
Does it support an externally created, offline root CA?Does it support custom EKUs?- Yes. Custom EKUs can be added to CAs during creation.
Does it support custom templates?- Cloud PKI does not use custom templates. All customization is done through the SCEP profile. See: Use SCEP certificate profiles with Microsoft Intune | Microsoft Learn
How does security works for enrollment, how do we limit who can request what certificates?- We utilize the SCEP protocol for certificate enrollment. The endpoint is secured so only those devices that have received SCEP enrollment requests through Intune will be able to receive certificates. When an Intune SCEP certificate profile is delivered to a device, Intune generates a custom challenge blob that it encrypts and signs. That challenge needs to be present in the request, or it will be rejected by the SCEP enrollment endpoint.
What methods and protocols does it support for enrollment other than SCEP?
- Certificate delivery for Cloud PKI is currently limited to SCEP certificates. If you are interested in seeing other scenarios supported in the future, please submit feedback to https://aka.ms/IntuneFeedback.
Can we issue certificates with custom properties similar to ADCS’ “supply in the request”, and how is that secured?
- Customization is currently limited to what can be done from within the SCEP profile. If there are additional properties you would like to be able to add to issued certificates, please give us feedback at https://aka.ms/IntuneFeedback