{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/",
        "slug": "dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/"
        },
        "title": "Give every eligible Intune PKCS connector access to all configured CAs",
        "summary": "Can an administrator pin each Intune PKCS request to a preferred certificate connector?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:11+00:00",
        "modified_at": "2026-09-10T01:40:03+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 231,
        "potentially_affected": "Apply this check when adding, replacing, or segmenting current Certificate Connector for Microsoft Intune instances. Inventory enabled features per instance; do not assume a connector's name establishes request affinity.",
        "dse_recommendation": "Review the connector fleet as a shared request-processing pool before claiming redundancy.",
        "primary_source": {
            "name": "Overview of Certificate Connector for Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/fundamentals/certificates/connector/overview",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Any Intune certificate connector with PKCS enabled can retrieve pending PKCS requests, process imported certificates, and handle revocation. Microsoft does not allow administrators to select which eligible connector handles a particular request. Consequently, each PKCS-enabled connector needs equivalent permissions and connectivity to every CA named in the PKCS profiles. Each connector instance also needs access to the private key protecting uploaded PFX-file passwords. <a href=\"https://learn.microsoft.com/en-us/intune/fundamentals/certificates/connector/overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this check when adding, replacing, or segmenting current Certificate Connector for Microsoft Intune instances. Inventory enabled features per instance; do not assume a connector&#8217;s name establishes request affinity.</p>\n<h2>DSE recommendation</h2>\n<p>Review the connector fleet as a shared request-processing pool before claiming redundancy. Build a connector-to-CA permission and reachability matrix, and have the PKI owner approve every required path. Include protected access to imported-certificate key material where that workload is used. Treat a connector that can process only a subset of the configured PKCS authorities as an unresolved design issue, rather than relying on a preferred server to win requests.</p>\n<h2>Verification</h2>\n<p>Use approved test profiles for each configured CA and correlate the resulting requests with connector logs. During a controlled redundancy exercise, verify issuance and the required lifecycle operations through the remaining eligible instances. Preserve identities, feature configuration, and outcomes without exporting private keys. Resolve inconsistent permissions before introducing additional connector capacity.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/fundamentals/certificates/connector/overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Overview of Certificate Connector for Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nAny Intune certificate connector with PKCS enabled can retrieve pending PKCS requests, process imported certificates, and handle revocation. Microsoft does not allow administrators to select which eligible connector handles a particular request. Consequently, each PKCS-enabled connector needs equivalent permissions and connectivity to every CA named in the PKCS profiles. Each connector instance also needs access to the private key protecting uploaded PFX-file passwords. Microsoft Learn.\nApplicability\nApply this check when adding, replacing, or segmenting current Certificate Connector for Microsoft Intune instances. Inventory enabled features per instance; do not assume a connector’s name establishes request affinity.\nDSE recommendation\nReview the connector fleet as a shared request-processing pool before claiming redundancy. Build a connector-to-CA permission and reachability matrix, and have the PKI owner approve every required path. Include protected access to imported-certificate key material where that workload is used. Treat a connector that can process only a subset of the configured PKCS authorities as an unresolved design issue, rather than relying on a preferred server to win requests.\nVerification\nUse approved test profiles for each configured CA and correlate the resulting requests with connector logs. During a controlled redundancy exercise, verify issuance and the required lifecycle operations through the remaining eligible instances. Preserve identities, feature configuration, and outcomes without exporting private keys. Resolve inconsistent permissions before introducing additional connector capacity.\nOfficial references\nMicrosoft Learn: Overview of Certificate Connector for Microsoft Intune.",
        "content_markdown": "## Source facts\n\nAny Intune certificate connector with PKCS enabled can retrieve pending PKCS requests, process imported certificates, and handle revocation. Microsoft does not allow administrators to select which eligible connector handles a particular request. Consequently, each PKCS-enabled connector needs equivalent permissions and connectivity to every CA named in the PKCS profiles. Each connector instance also needs access to the private key protecting uploaded PFX-file passwords. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/fundamentals/certificates/connector/overview).\n\n## Applicability\n\nApply this check when adding, replacing, or segmenting current Certificate Connector for Microsoft Intune instances. Inventory enabled features per instance; do not assume a connector’s name establishes request affinity.\n\n## DSE recommendation\n\nReview the connector fleet as a shared request-processing pool before claiming redundancy. Build a connector-to-CA permission and reachability matrix, and have the PKI owner approve every required path. Include protected access to imported-certificate key material where that workload is used. Treat a connector that can process only a subset of the configured PKCS authorities as an unresolved design issue, rather than relying on a preferred server to win requests.\n\n## Verification\n\nUse approved test profiles for each configured CA and correlate the resulting requests with connector logs. During a controlled redundancy exercise, verify issuance and the required lifecycle operations through the remaining eligible instances. Preserve identities, feature configuration, and outcomes without exporting private keys. Resolve inconsistent permissions before introducing additional connector capacity.\n\n## Official references\n\n[Microsoft Learn: Overview of Certificate Connector for Microsoft Intune](https://learn.microsoft.com/en-us/intune/fundamentals/certificates/connector/overview)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Give every eligible Intune PKCS connector access to all configured CAs",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/",
                "headline": "Give every eligible Intune PKCS connector access to all configured CAs",
                "description": "Can an administrator pin each Intune PKCS request to a preferred certificate connector?",
                "abstract": "Can an administrator pin each Intune PKCS request to a preferred certificate connector?",
                "articleBody": "Source facts\nAny Intune certificate connector with PKCS enabled can retrieve pending PKCS requests, process imported certificates, and handle revocation. Microsoft does not allow administrators to select which eligible connector handles a particular request. Consequently, each PKCS-enabled connector needs equivalent permissions and connectivity to every CA named in the PKCS profiles. Each connector instance also needs access to the private key protecting uploaded PFX-file passwords. Microsoft Learn.\nApplicability\nApply this check when adding, replacing, or segmenting current Certificate Connector for Microsoft Intune instances. Inventory enabled features per instance; do not assume a connector’s name establishes request affinity.\nDSE recommendation\nReview the connector fleet as a shared request-processing pool before claiming redundancy. Build a connector-to-CA permission and reachability matrix, and have the PKI owner approve every required path. Include protected access to imported-certificate key material where that workload is used. Treat a connector that can process only a subset of the configured PKCS authorities as an unresolved design issue, rather than relying on a preferred server to win requests.\nVerification\nUse approved test profiles for each configured CA and correlate the resulting requests with connector logs. During a controlled redundancy exercise, verify issuance and the required lifecycle operations through the remaining eligible instances. Preserve identities, feature configuration, and outcomes without exporting private keys. Resolve inconsistent permissions before introducing additional connector capacity.\nOfficial references\nMicrosoft Learn: Overview of Certificate Connector for Microsoft Intune.",
                "datePublished": "2026-09-10T00:26:11+00:00",
                "dateModified": "2026-09-10T01:40:03+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Give every eligible Intune PKCS connector access to all configured CAs"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 231,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Overview of Certificate Connector for Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/fundamentals/certificates/connector/overview"
                }
            }
        ]
    }
}