{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/",
        "slug": "dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/"
        },
        "title": "Complete the trust chain before enabling a Cloud PKI BYOCA issuer",
        "summary": "Which trust materials must accompany a signed Cloud PKI BYOCA certificate?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:30:06+00:00",
        "modified_at": "2026-09-10T00:52:38+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 227,
        "potentially_affected": "Apply this review to the BYOCA deployment model, not a new cloud-only root. Identify the private signing hierarchy, target device platforms, and systems that will accept the resulting client certificates.",
        "dse_recommendation": "Have the PKI owner produce a chain inventory before handing the signed request back to the Intune operator.",
        "primary_source": {
            "name": "Bring your own certificate authority with Cloud PKI - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/cloud-pki/configure-byoca",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Cloud PKI BYOCA anchors a cloud issuing CA in an existing private CA hierarchy. Enabling that issuer requires its signed certificate and the complete chain of the private signing CA. Intune requires trusted certificate profiles for every CA in that private hierarchy on each target platform. The downloaded BYOCA issuing certificate must also be installed on all relying parties. <a href=\"https://learn.microsoft.com/en-us/intune/cloud-pki/configure-byoca\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this review to the BYOCA deployment model, not a new cloud-only root. Identify the private signing hierarchy, target device platforms, and systems that will accept the resulting client certificates.</p>\n<h2>DSE recommendation</h2>\n<p>Have the PKI owner produce a chain inventory before handing the signed request back to the Intune operator. Match each required public certificate to a named profile or relying-party deployment owner. Compare certificate identities with the approved hierarchy and keep signing-key material out of this handoff. Treat a successful certificate upload as one checkpoint, not the entire acceptance decision.</p>\n<h2>Verification</h2>\n<p>Check the issuer state after uploading the signed certificate and chain. On an approved pilot, confirm that the intended trust profiles arrived and inspect the issued certificate path. Then exercise the actual certificate-authenticated service with its owner. Stop expansion if the endpoint and relying party disagree about the intended issuer or trust anchor; retain sanitized chain and test evidence.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/cloud-pki/configure-byoca\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Bring your own certificate authority with Cloud PKI</a>.</p>",
        "content_text": "Source facts\nCloud PKI BYOCA anchors a cloud issuing CA in an existing private CA hierarchy. Enabling that issuer requires its signed certificate and the complete chain of the private signing CA. Intune requires trusted certificate profiles for every CA in that private hierarchy on each target platform. The downloaded BYOCA issuing certificate must also be installed on all relying parties. Microsoft Learn.\nApplicability\nApply this review to the BYOCA deployment model, not a new cloud-only root. Identify the private signing hierarchy, target device platforms, and systems that will accept the resulting client certificates.\nDSE recommendation\nHave the PKI owner produce a chain inventory before handing the signed request back to the Intune operator. Match each required public certificate to a named profile or relying-party deployment owner. Compare certificate identities with the approved hierarchy and keep signing-key material out of this handoff. Treat a successful certificate upload as one checkpoint, not the entire acceptance decision.\nVerification\nCheck the issuer state after uploading the signed certificate and chain. On an approved pilot, confirm that the intended trust profiles arrived and inspect the issued certificate path. Then exercise the actual certificate-authenticated service with its owner. Stop expansion if the endpoint and relying party disagree about the intended issuer or trust anchor; retain sanitized chain and test evidence.\nOfficial references\nMicrosoft Learn: Bring your own certificate authority with Cloud PKI.",
        "content_markdown": "## Source facts\n\nCloud PKI BYOCA anchors a cloud issuing CA in an existing private CA hierarchy. Enabling that issuer requires its signed certificate and the complete chain of the private signing CA. Intune requires trusted certificate profiles for every CA in that private hierarchy on each target platform. The downloaded BYOCA issuing certificate must also be installed on all relying parties. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/cloud-pki/configure-byoca).\n\n## Applicability\n\nApply this review to the BYOCA deployment model, not a new cloud-only root. Identify the private signing hierarchy, target device platforms, and systems that will accept the resulting client certificates.\n\n## DSE recommendation\n\nHave the PKI owner produce a chain inventory before handing the signed request back to the Intune operator. Match each required public certificate to a named profile or relying-party deployment owner. Compare certificate identities with the approved hierarchy and keep signing-key material out of this handoff. Treat a successful certificate upload as one checkpoint, not the entire acceptance decision.\n\n## Verification\n\nCheck the issuer state after uploading the signed certificate and chain. On an approved pilot, confirm that the intended trust profiles arrived and inspect the issued certificate path. Then exercise the actual certificate-authenticated service with its owner. Stop expansion if the endpoint and relying party disagree about the intended issuer or trust anchor; retain sanitized chain and test evidence.\n\n## Official references\n\n[Microsoft Learn: Bring your own certificate authority with Cloud PKI](https://learn.microsoft.com/en-us/intune/cloud-pki/configure-byoca)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Complete the trust chain before enabling a Cloud PKI BYOCA issuer",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/",
                "headline": "Complete the trust chain before enabling a Cloud PKI BYOCA issuer",
                "description": "Which trust materials must accompany a signed Cloud PKI BYOCA certificate?",
                "abstract": "Which trust materials must accompany a signed Cloud PKI BYOCA certificate?",
                "articleBody": "Source facts\nCloud PKI BYOCA anchors a cloud issuing CA in an existing private CA hierarchy. Enabling that issuer requires its signed certificate and the complete chain of the private signing CA. Intune requires trusted certificate profiles for every CA in that private hierarchy on each target platform. The downloaded BYOCA issuing certificate must also be installed on all relying parties. Microsoft Learn.\nApplicability\nApply this review to the BYOCA deployment model, not a new cloud-only root. Identify the private signing hierarchy, target device platforms, and systems that will accept the resulting client certificates.\nDSE recommendation\nHave the PKI owner produce a chain inventory before handing the signed request back to the Intune operator. Match each required public certificate to a named profile or relying-party deployment owner. Compare certificate identities with the approved hierarchy and keep signing-key material out of this handoff. Treat a successful certificate upload as one checkpoint, not the entire acceptance decision.\nVerification\nCheck the issuer state after uploading the signed certificate and chain. On an approved pilot, confirm that the intended trust profiles arrived and inspect the issued certificate path. Then exercise the actual certificate-authenticated service with its owner. Stop expansion if the endpoint and relying party disagree about the intended issuer or trust anchor; retain sanitized chain and test evidence.\nOfficial references\nMicrosoft Learn: Bring your own certificate authority with Cloud PKI.",
                "datePublished": "2026-09-10T00:30:06+00:00",
                "dateModified": "2026-09-10T00:52:38+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Complete the trust chain before enabling a Cloud PKI BYOCA issuer"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 227,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Bring your own certificate authority with Cloud PKI - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/cloud-pki/configure-byoca"
                }
            }
        ]
    }
}