The latest addition, Microsoft Cloud PKI (Cloud PKI), brings a cloud-based service that streamlines and automates certificate lifecycle management for devices managed through Intune. Cloud PKI delivers a public key infrastructure (PKI) directly from the cloud, allowing organizations to set up a PKI environment in just a few minutes by following a few simple wizards. Even with a two-tier hierarchy involving a root certificate authority (CA) and an issuing CA, there’s no need for on-premises servers, connectors, or hardware. Cloud PKI takes care of certificate issuance, renewal, and revocation for Intune-managed devices, significantly simplifying many certificate scenarios. However, it's important to note that this solution is limited to Intune-managed devices. This post will guide you through the steps to create a two-tier hierarchy and use this setup for deploying certificates to Intune-managed devices.
In our lab, we've already got a 2 tier PKI setup using AD CS we will sign our cloud PKI using the issuing server. If you dont have a pre-existing PKI infrastructure and would like to create root CA in the cloud Click Me.
Once the root CA is established, either by creating it within Cloud PKI or using a bring-your-own CA (BYOCA) approach, the next step is to set up the issuing CA. This issuing CA will handle the certificate issuance for Intune-managed devices. During its creation, Cloud PKI automatically configures the Simple Certificate Enrollment Protocol (SCEP) service, which requests certificates from the issuing CA on behalf of the Intune-managed devices. The following six steps outline the process for creating the issuing CA within Cloud PKI—a straightforward procedure that highlights the ease of use Cloud PKI offers.
On the Tenant admin | Cloud PKI page, click Create.
On the Basics page, provide a valid name for the certification authority.
On the Configuration settings page, fill in the required details:
After completing the configuration, review the details and click Next.
Confirm the settings and click Create to finalize the process. The issuing CA will now be created within Cloud PKI.
After downloading the certificates, you can easily make them trusted by using a trusted certificate profile. This profile allows you to add the certificates to a specific store on the device. Follow these eight steps to distribute the certificates to the Trusted Root Certification Authorities store:
Enter Basic Profile Information
Configure Certificate Settings
Assign the Profile