# Complete the trust chain before enabling a Cloud PKI BYOCA issuer

> Which trust materials must accompany a signed Cloud PKI BYOCA certificate?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:06+00:00
- Modified: 2026-09-10T00:52:38+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Which trust materials must accompany a signed Cloud PKI BYOCA certificate?

## Potentially affected

Apply this review to the BYOCA deployment model, not a new cloud-only root. Identify the private signing hierarchy, target device platforms, and systems that will accept the resulting client certificates.

## DSE recommendation

Have the PKI owner produce a chain inventory before handing the signed request back to the Intune operator.

## Article

## Source facts

Cloud PKI BYOCA anchors a cloud issuing CA in an existing private CA hierarchy. Enabling that issuer requires its signed certificate and the complete chain of the private signing CA. Intune requires trusted certificate profiles for every CA in that private hierarchy on each target platform. The downloaded BYOCA issuing certificate must also be installed on all relying parties. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/cloud-pki/configure-byoca).

## Applicability

Apply this review to the BYOCA deployment model, not a new cloud-only root. Identify the private signing hierarchy, target device platforms, and systems that will accept the resulting client certificates.

## DSE recommendation

Have the PKI owner produce a chain inventory before handing the signed request back to the Intune operator. Match each required public certificate to a named profile or relying-party deployment owner. Compare certificate identities with the approved hierarchy and keep signing-key material out of this handoff. Treat a successful certificate upload as one checkpoint, not the entire acceptance decision.

## Verification

Check the issuer state after uploading the signed certificate and chain. On an approved pilot, confirm that the intended trust profiles arrived and inspect the issued certificate path. Then exercise the actual certificate-authenticated service with its owner. Stop expansion if the endpoint and relying party disagree about the intended issuer or trust anchor; retain sanitized chain and test evidence.

## Official references

[Microsoft Learn: Bring your own certificate authority with Cloud PKI](https://learn.microsoft.com/en-us/intune/cloud-pki/configure-byoca).

## Primary reference

- Name: Bring your own certificate authority with Cloud PKI - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/cloud-pki/configure-byoca
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Complete the trust chain before enabling a Cloud PKI BYOCA issuer,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-110-complete-the-trust-chain-before-enabling-a-cloud-pki-byoca-issuer/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
