Can Microsoft Intune be integrated with MTG Corporate PKI & CLM?
Yes, Microsoft Intune can be integrated with MTG Corporate PKI & CLM through MTG SCEP. Microsoft Intune remains responsible for endpoint management and distribution of certificate profiles, while certificates are issued by MTG Corporate PKI and managed through MTG CLM. This allows companies to continue using Microsoft Intune for endpoint management without relying on Microsoft […]
Is there a migration path from Microsoft AD CS to Microsoft Cloud PKI?
A direct 1:1 migration from Microsoft AD CS to Microsoft Cloud PKI is not intended. Microsoft Cloud PKI is primarily designed to provide certificates to Intune-managed devices and therefore does not automatically replace all existing AD CS use cases. Companies that want to replace or modernize their existing Microsoft PKI therefore often need a solution […]
Can customer-owned keys or HSMs be connected to Microsoft Cloud PKI?
The keys used by Microsoft Cloud PKI are protected within Microsoft’s cloud infrastructure. A customer-owned HSM or third-party HSM cannot be used directly as the key store for a Microsoft-managed Cloud PKI CA. For companies that need to retain control over key material and HSM infrastructure for regulatory, organizational, or security reasons, operating their own […]
Does Microsoft Cloud PKI provide Certificate Lifecycle Management?
Yes, Microsoft Cloud PKI provides basic lifecycle management capabilities within the Intune environment. Certificates for Intune-managed devices can be automatically issued, distributed, renewed, and revoked. From an enterprise-wide Certificate Lifecycle Management perspective, however, the functionality is limited because management focuses on the devices and use cases supported by Intune. MTG CLM, by contrast, is designed […]
Which key lengths are available in Microsoft Cloud PKI?
Microsoft Cloud PKI currently supports RSA keys with lengths of 2048, 3072, and 4096 bits, as well as the SHA-256, SHA-384, and SHA-512 hash algorithms. This is sufficient for many traditional use cases. However, companies that want to consider additional cryptographic methods or emerging technologies such as ECC or Post-Quantum Cryptography over the long term […]
Are there limitations when configuring Microsoft Cloud PKI?
Yes, compared with a freely configurable enterprise PKI, Microsoft Cloud PKI provides more limited options for PKI architecture and configuration. Only certain CA hierarchies and a limited number of Certification Authorities can be operated within an Intune tenant. In addition, certain CA properties cannot be flexibly changed after the CA has been created. For companies […]
Microsoft Intune & Cloud PKI – Where does this service run, and are there any limitations?
Microsoft Cloud PKI is operated entirely as a cloud service within the Microsoft environment. With a fully Microsoft-managed Cloud PKI, no local CA, NDES, or Certificate Connector components are required. This is particularly attractive for companies that want to implement certificate provisioning entirely in the cloud and exclusively for Intune-managed endpoints. At the same time, […]
What functions does Microsoft Cloud PKI provide in combination with Microsoft Intune, and what limitations are there?
Microsoft Cloud PKI is primarily designed for the automated provisioning of certificates to devices managed through Microsoft Intune. Certificates can be automatically issued, distributed, and renewed through SCEP profiles. Typical use cases include certificate-based authentication for Wi-Fi or VPN access. From an enterprise-wide PKI perspective, however, the functionality is limited because the solution is primarily […]