Event banner
Utilize, configure, and manage Cloud PKI like a pro
Event details
Microsoft Cloud PKI in depth! Start with a tour of the significant improvements made to this Microsoft Intune Suite feature since its release in March 2024. We’ll then offer comprehensive guidance for several critical areas:
- Proper deletion of a certificate authority: Learn the essential steps to correctly delete a certificate authority, ensuring a smooth and error-free process.
- Microsoft NPS (RADIUS) configuration: Get expert advice on configuring Network Policy Server (NPS) when using Cloud PKI, including best practices and common pitfalls to avoid.
- Upcoming leaf certificate reporting improvements: Discover the new enhancements in leaf certificate reporting that will soon be released and understand how they can benefit your organization.
- SCEP certificate profile configuration: Gain insights into the common challenges and solutions when configuring a SCEP certificate profile so you can streamline your setup and avoid potential issues.
This session is designed for IT professionals and administrators who are looking to deepen their understanding of Cloud PKI and get up-to-date on the latest advancements. Don't miss this opportunity to enhance your skills and help ensure your organization's PKI infrastructure is optimized for success.
Speakers: Bill Calero, Jack Poehlman
This session is part of Microsoft Technical Takeoff: Windows and Intune.
39 Comments
- richardhicksCopper Contributor
The issuing CA certificates for Intune Cloud PKI do not include CDP information. How is reovcation of an issuing CA checked without it?
- Bill Calero
Microsoft
Hey richardhicks ... we do provide a CRL CDP for all CA's... are you referring to a different CDP .. can you clarify?
- richardhicksCopper Contributor
The issuing CA certificate for my cloud PKI instance does not have CDP information, which causes problems for NPS because it fails a revocation check. Certutil.exe -verify reports "Revocation check skipped - no revocation information available" when checking the issuing CA certificate.
- Roger_TrussBrass Contributor
Will there be a roadmap for Linux? Even if it's a script, support for that Platform would be greatly appreciated due to Wi-Fi cisco requiremetns.
- Bill Calero
Microsoft
I'm a long time Linux supporter .. inside secret - I worked at SuSE linux for a few years :-)
Unfortunately, as you know we dont have linux SCEP cert profile support ATM. I would love to get this addressed, but have no roadmap commitment to share. - Jack_Poehlman
Microsoft
We'd love to hear specifically what you are looking for in this scenario. Please let us know at aka.ms/IntuneFeedback
- dmuscatOccasional Reader
Can I use this solution to generate certs for SSO configs, websites, LDAPS, etc... for non intune solutions?
- dmuscatOccasional Reader
Ok I can see it was covered by BYOCA. Question now is that can I manage those CA's thru the Cloud PKI portal UI or do I still need to use traditional means for that mgmt?
- Bill Calero
Microsoft
Good question, C-PKI can issue a cert to any Intune enrolled and managed device - platforms supported: Windows, iOS, macOS, Android. If the device is not enrolled in Intune we cannot issue a cert. Note: an issued cert to any of these platforms can provide cert-based-auth to websites, apps and resource access endpoints like WiFi, VPN - providing an SSO experience.
- ucbryanweaverCopper Contributor
Is Cloud PKI licensed per device or per user?
- Jack_Poehlman
Microsoft
Per user with either Intune Suite or the Cloud PKI SKU
- ucbryanweaverCopper Contributor
Would I have to license Cloud PKI for everyone, or can I just do a subset?
- ucbryanweaverCopper Contributor
Does Cloud PKI work with hybrid joined devices?
- Bill Calero
Microsoft
Absolutely, C-PKI can issue a cert to a hybrid joined device that is managed by Intune.
- Heather_Poulsen
Community Manager
Welcome to “Utilize, configure, and manage Cloud PKI like a pro” at Microsoft Technical Takeoff. Q&A is open now and throughout the week. Please post any questions or feedback here in the Comments.