{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/",
        "slug": "dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/"
        },
        "title": "Treat derived-credential issuer recreation as a credential migration",
        "summary": "Can deleting and re-adding the same Intune derived-credential issuer preserve existing device credentials?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:34+00:00",
        "modified_at": "2026-09-10T02:04:58+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 211,
        "potentially_affected": "Apply this change-impact check before deleting a derived-credential issuer as a troubleshooting step. Inventory the profiles, supported device populations, and authentication workflows that depend on it.",
        "dse_recommendation": "Plan issuer replacement as a coordinated credential transition with user assistance and application-owner participation.",
        "primary_source": {
            "name": "Use derived credentials for mobile devices with Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-security/certificates/derived-credentials",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>An Intune tenant supports only one derived-credential issuer at a time. Deleting an issuer invalidates credentials previously obtained through it, even if the same issuer is immediately recreated. Profiles using derived credentials must then be edited to trigger an update, and device users must request new credentials. Restoring the same issuer does not remove either requirement. <a href=\"https://learn.microsoft.com/en-us/intune/device-security/certificates/derived-credentials\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this change-impact check before deleting a derived-credential issuer as a troubleshooting step. Inventory the profiles, supported device populations, and authentication workflows that depend on it.</p>\n<h2>DSE recommendation</h2>\n<p>Plan issuer replacement as a coordinated credential transition with user assistance and application-owner participation. Preserve the configuration inventory, but do not label recreation of the old issuer a credential-preserving rollback. Arrange an approved alternative support path and clear instructions for obtaining the new credential before any disruptive change.</p>\n<h2>Verification</h2>\n<p>In an authorized test arrangement, follow profile update and new-credential enrollment through the required application or network authentication. Record which profiles and users have completed the transition and which still require assistance. Verify the actual credential in use rather than accepting the reappearance of the issuer name in the portal as recovery. Keep private credential material outside general change records.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-security/certificates/derived-credentials\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Use derived credentials for mobile devices with Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nAn Intune tenant supports only one derived-credential issuer at a time. Deleting an issuer invalidates credentials previously obtained through it, even if the same issuer is immediately recreated. Profiles using derived credentials must then be edited to trigger an update, and device users must request new credentials. Restoring the same issuer does not remove either requirement. Microsoft Learn.\nApplicability\nApply this change-impact check before deleting a derived-credential issuer as a troubleshooting step. Inventory the profiles, supported device populations, and authentication workflows that depend on it.\nDSE recommendation\nPlan issuer replacement as a coordinated credential transition with user assistance and application-owner participation. Preserve the configuration inventory, but do not label recreation of the old issuer a credential-preserving rollback. Arrange an approved alternative support path and clear instructions for obtaining the new credential before any disruptive change.\nVerification\nIn an authorized test arrangement, follow profile update and new-credential enrollment through the required application or network authentication. Record which profiles and users have completed the transition and which still require assistance. Verify the actual credential in use rather than accepting the reappearance of the issuer name in the portal as recovery. Keep private credential material outside general change records.\nOfficial references\nMicrosoft Learn: Use derived credentials for mobile devices with Microsoft Intune.",
        "content_markdown": "## Source facts\n\nAn Intune tenant supports only one derived-credential issuer at a time. Deleting an issuer invalidates credentials previously obtained through it, even if the same issuer is immediately recreated. Profiles using derived credentials must then be edited to trigger an update, and device users must request new credentials. Restoring the same issuer does not remove either requirement. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-security/certificates/derived-credentials).\n\n## Applicability\n\nApply this change-impact check before deleting a derived-credential issuer as a troubleshooting step. Inventory the profiles, supported device populations, and authentication workflows that depend on it.\n\n## DSE recommendation\n\nPlan issuer replacement as a coordinated credential transition with user assistance and application-owner participation. Preserve the configuration inventory, but do not label recreation of the old issuer a credential-preserving rollback. Arrange an approved alternative support path and clear instructions for obtaining the new credential before any disruptive change.\n\n## Verification\n\nIn an authorized test arrangement, follow profile update and new-credential enrollment through the required application or network authentication. Record which profiles and users have completed the transition and which still require assistance. Verify the actual credential in use rather than accepting the reappearance of the issuer name in the portal as recovery. Keep private credential material outside general change records.\n\n## Official references\n\n[Microsoft Learn: Use derived credentials for mobile devices with Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-security/certificates/derived-credentials)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Treat derived-credential issuer recreation as a credential migration",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/",
                "headline": "Treat derived-credential issuer recreation as a credential migration",
                "description": "Can deleting and re-adding the same Intune derived-credential issuer preserve existing device credentials?",
                "abstract": "Can deleting and re-adding the same Intune derived-credential issuer preserve existing device credentials?",
                "articleBody": "Source facts\nAn Intune tenant supports only one derived-credential issuer at a time. Deleting an issuer invalidates credentials previously obtained through it, even if the same issuer is immediately recreated. Profiles using derived credentials must then be edited to trigger an update, and device users must request new credentials. Restoring the same issuer does not remove either requirement. Microsoft Learn.\nApplicability\nApply this change-impact check before deleting a derived-credential issuer as a troubleshooting step. Inventory the profiles, supported device populations, and authentication workflows that depend on it.\nDSE recommendation\nPlan issuer replacement as a coordinated credential transition with user assistance and application-owner participation. Preserve the configuration inventory, but do not label recreation of the old issuer a credential-preserving rollback. Arrange an approved alternative support path and clear instructions for obtaining the new credential before any disruptive change.\nVerification\nIn an authorized test arrangement, follow profile update and new-credential enrollment through the required application or network authentication. Record which profiles and users have completed the transition and which still require assistance. Verify the actual credential in use rather than accepting the reappearance of the issuer name in the portal as recovery. Keep private credential material outside general change records.\nOfficial references\nMicrosoft Learn: Use derived credentials for mobile devices with Microsoft Intune.",
                "datePublished": "2026-09-10T00:24:34+00:00",
                "dateModified": "2026-09-10T02:04:58+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Treat derived-credential issuer recreation as a credential migration"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 211,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use derived credentials for mobile devices with Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-security/certificates/derived-credentials"
                }
            }
        ]
    }
}