{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal/",
        "slug": "dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal/"
        },
        "title": "Test the staged Cloud PKI issuer before activating renewal",
        "summary": "What must be validated while a renewed Cloud PKI issuer is still staged?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:26+00:00",
        "modified_at": "2026-09-10T00:52:39+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 220,
        "potentially_affected": "Limit this plan to issuing-CA renewal. For BYOCA, Microsoft requires the renewal request to be signed by the private CA that issued the original certificate. Confirm that signing handoff before setting the test schedule.",
        "dse_recommendation": "Reserve a small test group and name the production and staged CA versions explicitly.",
        "primary_source": {
            "name": "Renew a Certificate Authority in Cloud PKI - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/cloud-pki/renew-ca",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Cloud PKI renewal supports Intune-managed and BYOCA issuing CAs and always generates a new key pair. Staging provides a separate test SCEP address for up to 90 days, with a maximum of 50 test certificates. Activation retires the old CA version and restores the original production SCEP address. Earlier certificates and revocation lists remain available. <a href=\"https://learn.microsoft.com/en-us/intune/cloud-pki/renew-ca\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Limit this plan to issuing-CA renewal. For BYOCA, Microsoft requires the renewal request to be signed by the private CA that issued the original certificate. Confirm that signing handoff before setting the test schedule.</p>\n<h2>DSE recommendation</h2>\n<p>Reserve a small test group and name the production and staged CA versions explicitly. Set an owner and activation deadline within the staging window. Define the certificate purposes and relying-party checks that must pass before promotion; budget the limited test issuances deliberately. Keep the production profile separate from the temporary test profile throughout validation.</p>\n<h2>Verification</h2>\n<p>Issue test certificates through the staged address and inspect their issuer, intended purpose, and actual service authentication. Obtain the PKI owner’s acceptance before activation. Afterward, verify the active version and the original production address, and remove the test profile as Microsoft directs. Record any failed test as unresolved rather than treating creation of the staged object as completed renewal.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/cloud-pki/renew-ca\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Renew a Certificate Authority in Cloud PKI</a>.</p>",
        "content_text": "Source facts\nCloud PKI renewal supports Intune-managed and BYOCA issuing CAs and always generates a new key pair. Staging provides a separate test SCEP address for up to 90 days, with a maximum of 50 test certificates. Activation retires the old CA version and restores the original production SCEP address. Earlier certificates and revocation lists remain available. Microsoft Learn.\nApplicability\nLimit this plan to issuing-CA renewal. For BYOCA, Microsoft requires the renewal request to be signed by the private CA that issued the original certificate. Confirm that signing handoff before setting the test schedule.\nDSE recommendation\nReserve a small test group and name the production and staged CA versions explicitly. Set an owner and activation deadline within the staging window. Define the certificate purposes and relying-party checks that must pass before promotion; budget the limited test issuances deliberately. Keep the production profile separate from the temporary test profile throughout validation.\nVerification\nIssue test certificates through the staged address and inspect their issuer, intended purpose, and actual service authentication. Obtain the PKI owner’s acceptance before activation. Afterward, verify the active version and the original production address, and remove the test profile as Microsoft directs. Record any failed test as unresolved rather than treating creation of the staged object as completed renewal.\nOfficial references\nMicrosoft Learn: Renew a Certificate Authority in Cloud PKI.",
        "content_markdown": "## Source facts\n\nCloud PKI renewal supports Intune-managed and BYOCA issuing CAs and always generates a new key pair. Staging provides a separate test SCEP address for up to 90 days, with a maximum of 50 test certificates. Activation retires the old CA version and restores the original production SCEP address. Earlier certificates and revocation lists remain available. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/cloud-pki/renew-ca).\n\n## Applicability\n\nLimit this plan to issuing-CA renewal. For BYOCA, Microsoft requires the renewal request to be signed by the private CA that issued the original certificate. Confirm that signing handoff before setting the test schedule.\n\n## DSE recommendation\n\nReserve a small test group and name the production and staged CA versions explicitly. Set an owner and activation deadline within the staging window. Define the certificate purposes and relying-party checks that must pass before promotion; budget the limited test issuances deliberately. Keep the production profile separate from the temporary test profile throughout validation.\n\n## Verification\n\nIssue test certificates through the staged address and inspect their issuer, intended purpose, and actual service authentication. Obtain the PKI owner’s acceptance before activation. Afterward, verify the active version and the original production address, and remove the test profile as Microsoft directs. Record any failed test as unresolved rather than treating creation of the staged object as completed renewal.\n\n## Official references\n\n[Microsoft Learn: Renew a Certificate Authority in Cloud PKI](https://learn.microsoft.com/en-us/intune/cloud-pki/renew-ca)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Test the staged Cloud PKI issuer before activating renewal",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal/",
                "headline": "Test the staged Cloud PKI issuer before activating renewal",
                "description": "What must be validated while a renewed Cloud PKI issuer is still staged?",
                "abstract": "What must be validated while a renewed Cloud PKI issuer is still staged?",
                "articleBody": "Source facts\nCloud PKI renewal supports Intune-managed and BYOCA issuing CAs and always generates a new key pair. Staging provides a separate test SCEP address for up to 90 days, with a maximum of 50 test certificates. Activation retires the old CA version and restores the original production SCEP address. Earlier certificates and revocation lists remain available. Microsoft Learn.\nApplicability\nLimit this plan to issuing-CA renewal. For BYOCA, Microsoft requires the renewal request to be signed by the private CA that issued the original certificate. Confirm that signing handoff before setting the test schedule.\nDSE recommendation\nReserve a small test group and name the production and staged CA versions explicitly. Set an owner and activation deadline within the staging window. Define the certificate purposes and relying-party checks that must pass before promotion; budget the limited test issuances deliberately. Keep the production profile separate from the temporary test profile throughout validation.\nVerification\nIssue test certificates through the staged address and inspect their issuer, intended purpose, and actual service authentication. Obtain the PKI owner’s acceptance before activation. Afterward, verify the active version and the original production address, and remove the test profile as Microsoft directs. Record any failed test as unresolved rather than treating creation of the staged object as completed renewal.\nOfficial references\nMicrosoft Learn: Renew a Certificate Authority in Cloud PKI.",
                "datePublished": "2026-09-10T00:29:26+00:00",
                "dateModified": "2026-09-10T00:52:39+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-150-test-the-staged-cloud-pki-issuer-before-activating-renewal/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Test the staged Cloud PKI issuer before activating renewal"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 220,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Renew a Certificate Authority in Cloud PKI - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/cloud-pki/renew-ca"
                }
            }
        ]
    }
}