Microsoft Cloud PKI is primarily designed for the automated provisioning of certificates to devices managed through Microsoft Intune. Certificates can be automatically issued, distributed, and renewed through SCEP profiles. Typical use cases include certificate-based authentication for Wi-Fi or VPN access.
From an enterprise-wide PKI perspective, however, the functionality is limited because the solution is primarily focused on Intune-managed endpoints. Servers, network devices, applications, or other systems outside of Intune management cannot be centrally provisioned with certificates in the same way. Companies with heterogeneous infrastructures therefore often require a broader PKI and CLM solution.