{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key/",
        "slug": "dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key/"
        },
        "title": "Separate PKCS template export permission from the installed device key",
        "summary": "Why does Intune PKCS delivery require an exportable template even though the device key is marked nonexportable?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:10+00:00",
        "modified_at": "2026-09-10T02:08:04+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 254,
        "potentially_affected": "Review this distinction when approving a PKCS template or investigating a failed certificate delivery. Identify the connector-generated credential path rather than importing assumptions from a device-generated SCEP key.",
        "dse_recommendation": "Document the temporary delivery requirement and the intended installed-key property as separate security decisions.",
        "primary_source": {
            "name": "Use a PKCS certificate profile to provision devices with certificates in Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-configuration/certificates/pkcs-profiles",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For Intune PKCS delivery, the private key is generated on the certificate-connector server, not on the receiving device. The CA template must permit export so the connector can package the certificate as PFX and deliver it to the device. Once installed on the device, the private key is marked nonexportable. <a href=\"https://learn.microsoft.com/en-us/intune/device-configuration/certificates/pkcs-profiles\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review this distinction when approving a PKCS template or investigating a failed certificate delivery. Identify the connector-generated credential path rather than importing assumptions from a device-generated SCEP key.</p>\n<h2>DSE recommendation</h2>\n<p>Document the temporary delivery requirement and the intended installed-key property as separate security decisions. Ask the PKI owner to review the exact published template and its authorized connector accounts. Do not broaden export permissions on unrelated templates to solve one deployment problem. Include the connector host in the key-handling review instead of treating the device&#8217;s final setting as a description of the whole issuance path.</p>\n<h2>Verification</h2>\n<p>Issue a controlled test certificate through the approved PKCS profile. Confirm delivery through the intended template. Inspect the installed key property only on a platform exposing it through an authorized method. Android Enterprise does not display PKCS-profile certificates on the device; Microsoft directs administrators to the profile status in Intune to confirm deployment. <a href=\"https://learn.microsoft.com/en-us/intune/device-configuration/certificates/pkcs-profiles\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>. Correlate the issuance record with the test identity and connector operation. Keep the evidence focused on configuration and results; do not export a production private key merely to demonstrate the distinction.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-configuration/certificates/pkcs-profiles\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Use a PKCS certificate profile to provision devices with certificates in Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nFor Intune PKCS delivery, the private key is generated on the certificate-connector server, not on the receiving device. The CA template must permit export so the connector can package the certificate as PFX and deliver it to the device. Once installed on the device, the private key is marked nonexportable. Microsoft Learn.\nApplicability\nReview this distinction when approving a PKCS template or investigating a failed certificate delivery. Identify the connector-generated credential path rather than importing assumptions from a device-generated SCEP key.\nDSE recommendation\nDocument the temporary delivery requirement and the intended installed-key property as separate security decisions. Ask the PKI owner to review the exact published template and its authorized connector accounts. Do not broaden export permissions on unrelated templates to solve one deployment problem. Include the connector host in the key-handling review instead of treating the device’s final setting as a description of the whole issuance path.\nVerification\nIssue a controlled test certificate through the approved PKCS profile. Confirm delivery through the intended template. Inspect the installed key property only on a platform exposing it through an authorized method. Android Enterprise does not display PKCS-profile certificates on the device; Microsoft directs administrators to the profile status in Intune to confirm deployment. Microsoft Learn. Correlate the issuance record with the test identity and connector operation. Keep the evidence focused on configuration and results; do not export a production private key merely to demonstrate the distinction.\nOfficial references\nMicrosoft Learn: Use a PKCS certificate profile to provision devices with certificates in Microsoft Intune.",
        "content_markdown": "## Source facts\n\nFor Intune PKCS delivery, the private key is generated on the certificate-connector server, not on the receiving device. The CA template must permit export so the connector can package the certificate as PFX and deliver it to the device. Once installed on the device, the private key is marked nonexportable. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-configuration/certificates/pkcs-profiles).\n\n## Applicability\n\nReview this distinction when approving a PKCS template or investigating a failed certificate delivery. Identify the connector-generated credential path rather than importing assumptions from a device-generated SCEP key.\n\n## DSE recommendation\n\nDocument the temporary delivery requirement and the intended installed-key property as separate security decisions. Ask the PKI owner to review the exact published template and its authorized connector accounts. Do not broaden export permissions on unrelated templates to solve one deployment problem. Include the connector host in the key-handling review instead of treating the device’s final setting as a description of the whole issuance path.\n\n## Verification\n\nIssue a controlled test certificate through the approved PKCS profile. Confirm delivery through the intended template. Inspect the installed key property only on a platform exposing it through an authorized method. Android Enterprise does not display PKCS-profile certificates on the device; Microsoft directs administrators to the profile status in Intune to confirm deployment. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-configuration/certificates/pkcs-profiles). Correlate the issuance record with the test identity and connector operation. Keep the evidence focused on configuration and results; do not export a production private key merely to demonstrate the distinction.\n\n## Official references\n\n[Microsoft Learn: Use a PKCS certificate profile to provision devices with certificates in Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-configuration/certificates/pkcs-profiles)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate PKCS template export permission from the installed device key",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key/",
                "headline": "Separate PKCS template export permission from the installed device key",
                "description": "Why does Intune PKCS delivery require an exportable template even though the device key is marked nonexportable?",
                "abstract": "Why does Intune PKCS delivery require an exportable template even though the device key is marked nonexportable?",
                "articleBody": "Source facts\nFor Intune PKCS delivery, the private key is generated on the certificate-connector server, not on the receiving device. The CA template must permit export so the connector can package the certificate as PFX and deliver it to the device. Once installed on the device, the private key is marked nonexportable. Microsoft Learn.\nApplicability\nReview this distinction when approving a PKCS template or investigating a failed certificate delivery. Identify the connector-generated credential path rather than importing assumptions from a device-generated SCEP key.\nDSE recommendation\nDocument the temporary delivery requirement and the intended installed-key property as separate security decisions. Ask the PKI owner to review the exact published template and its authorized connector accounts. Do not broaden export permissions on unrelated templates to solve one deployment problem. Include the connector host in the key-handling review instead of treating the device’s final setting as a description of the whole issuance path.\nVerification\nIssue a controlled test certificate through the approved PKCS profile. Confirm delivery through the intended template. Inspect the installed key property only on a platform exposing it through an authorized method. Android Enterprise does not display PKCS-profile certificates on the device; Microsoft directs administrators to the profile status in Intune to confirm deployment. Microsoft Learn. Correlate the issuance record with the test identity and connector operation. Keep the evidence focused on configuration and results; do not export a production private key merely to demonstrate the distinction.\nOfficial references\nMicrosoft Learn: Use a PKCS certificate profile to provision devices with certificates in Microsoft Intune.",
                "datePublished": "2026-09-10T00:24:10+00:00",
                "dateModified": "2026-09-10T02:08:04+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-466-separate-pkcs-template-export-permission-from-the-installed-device-key/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate PKCS template export permission from the installed device key"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 254,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use a PKCS certificate profile to provision devices with certificates in Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-configuration/certificates/pkcs-profiles"
                }
            }
        ]
    }
}