{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/",
        "slug": "dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/"
        },
        "title": "Separate pausing a Cloud PKI issuer from permanently retiring it",
        "summary": "Is the intended Cloud PKI action a temporary issuance stop or irreversible decommissioning?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:52+00:00",
        "modified_at": "2026-09-10T01:40:02+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 228,
        "potentially_affected": "Use this review for an explicitly approved Cloud PKI decommissioning decision. Identify the exact CA and its issued certificates before selecting any lifecycle action.",
        "dse_recommendation": "Separate the request to stop new issuance from authorization to invalidate existing credentials.",
        "primary_source": {
            "name": "Delete issued PKI certificates with Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/cloud-pki/delete-ca",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Pausing a Cloud PKI issuing CA stops leaf issuance but keeps revocation-list and AIA responses available. The pause can be reversed. Revocation and deletion cannot be undone: active leaf certificates must be revoked before their issuer, and an anchored issuing CA must be deleted before its root. Microsoft says issuer revocation ends authentication of its existing leaf certificates. <a href=\"https://learn.microsoft.com/en-us/intune/cloud-pki/delete-ca\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review for an explicitly approved Cloud PKI decommissioning decision. Identify the exact CA and its issued certificates before selecting any lifecycle action.</p>\n<h2>DSE recommendation</h2>\n<p>Separate the request to stop new issuance from authorization to invalidate existing credentials. Map the affected certificate users and relying services, and require their owners to accept the replacement path before revocation. Record whether the proposal is a reversible pause or permanent retirement. Do not run the source’s bulk-revocation example merely to clean up a crowded console.</p>\n<h2>Verification</h2>\n<p>For an approved pause, confirm the intended CA’s status and compare the observed issuance behavior with the agreed stop condition. Before a permanent step, reconcile active leaf certificates and dependent issuers with the retirement inventory. Use a nonproduction rehearsal for the planned order and replacement authentication. Retain approval and final state evidence outside the disappearing CA object; a successful deletion is not proof that dependent services remain usable.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/cloud-pki/delete-ca\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Delete issued PKI certificates with Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nPausing a Cloud PKI issuing CA stops leaf issuance but keeps revocation-list and AIA responses available. The pause can be reversed. Revocation and deletion cannot be undone: active leaf certificates must be revoked before their issuer, and an anchored issuing CA must be deleted before its root. Microsoft says issuer revocation ends authentication of its existing leaf certificates. Microsoft Learn.\nApplicability\nUse this review for an explicitly approved Cloud PKI decommissioning decision. Identify the exact CA and its issued certificates before selecting any lifecycle action.\nDSE recommendation\nSeparate the request to stop new issuance from authorization to invalidate existing credentials. Map the affected certificate users and relying services, and require their owners to accept the replacement path before revocation. Record whether the proposal is a reversible pause or permanent retirement. Do not run the source’s bulk-revocation example merely to clean up a crowded console.\nVerification\nFor an approved pause, confirm the intended CA’s status and compare the observed issuance behavior with the agreed stop condition. Before a permanent step, reconcile active leaf certificates and dependent issuers with the retirement inventory. Use a nonproduction rehearsal for the planned order and replacement authentication. Retain approval and final state evidence outside the disappearing CA object; a successful deletion is not proof that dependent services remain usable.\nOfficial references\nMicrosoft Learn: Delete issued PKI certificates with Microsoft Intune.",
        "content_markdown": "## Source facts\n\nPausing a Cloud PKI issuing CA stops leaf issuance but keeps revocation-list and AIA responses available. The pause can be reversed. Revocation and deletion cannot be undone: active leaf certificates must be revoked before their issuer, and an anchored issuing CA must be deleted before its root. Microsoft says issuer revocation ends authentication of its existing leaf certificates. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/cloud-pki/delete-ca).\n\n## Applicability\n\nUse this review for an explicitly approved Cloud PKI decommissioning decision. Identify the exact CA and its issued certificates before selecting any lifecycle action.\n\n## DSE recommendation\n\nSeparate the request to stop new issuance from authorization to invalidate existing credentials. Map the affected certificate users and relying services, and require their owners to accept the replacement path before revocation. Record whether the proposal is a reversible pause or permanent retirement. Do not run the source’s bulk-revocation example merely to clean up a crowded console.\n\n## Verification\n\nFor an approved pause, confirm the intended CA’s status and compare the observed issuance behavior with the agreed stop condition. Before a permanent step, reconcile active leaf certificates and dependent issuers with the retirement inventory. Use a nonproduction rehearsal for the planned order and replacement authentication. Retain approval and final state evidence outside the disappearing CA object; a successful deletion is not proof that dependent services remain usable.\n\n## Official references\n\n[Microsoft Learn: Delete issued PKI certificates with Microsoft Intune](https://learn.microsoft.com/en-us/intune/cloud-pki/delete-ca)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate pausing a Cloud PKI issuer from permanently retiring it",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/",
                "headline": "Separate pausing a Cloud PKI issuer from permanently retiring it",
                "description": "Is the intended Cloud PKI action a temporary issuance stop or irreversible decommissioning?",
                "abstract": "Is the intended Cloud PKI action a temporary issuance stop or irreversible decommissioning?",
                "articleBody": "Source facts\nPausing a Cloud PKI issuing CA stops leaf issuance but keeps revocation-list and AIA responses available. The pause can be reversed. Revocation and deletion cannot be undone: active leaf certificates must be revoked before their issuer, and an anchored issuing CA must be deleted before its root. Microsoft says issuer revocation ends authentication of its existing leaf certificates. Microsoft Learn.\nApplicability\nUse this review for an explicitly approved Cloud PKI decommissioning decision. Identify the exact CA and its issued certificates before selecting any lifecycle action.\nDSE recommendation\nSeparate the request to stop new issuance from authorization to invalidate existing credentials. Map the affected certificate users and relying services, and require their owners to accept the replacement path before revocation. Record whether the proposal is a reversible pause or permanent retirement. Do not run the source’s bulk-revocation example merely to clean up a crowded console.\nVerification\nFor an approved pause, confirm the intended CA’s status and compare the observed issuance behavior with the agreed stop condition. Before a permanent step, reconcile active leaf certificates and dependent issuers with the retirement inventory. Use a nonproduction rehearsal for the planned order and replacement authentication. Retain approval and final state evidence outside the disappearing CA object; a successful deletion is not proof that dependent services remain usable.\nOfficial references\nMicrosoft Learn: Delete issued PKI certificates with Microsoft Intune.",
                "datePublished": "2026-09-10T00:26:52+00:00",
                "dateModified": "2026-09-10T01:40:02+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate pausing a Cloud PKI issuer from permanently retiring it"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 228,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Delete issued PKI certificates with Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/cloud-pki/delete-ca"
                }
            }
        ]
    }
}