GuideInformationBusiness ContinuityIT

Complete the trust chain before enabling a Cloud PKI BYOCA issuer

Which trust materials must accompany a signed Cloud PKI BYOCA certificate?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

Which trust materials must accompany a signed Cloud PKI BYOCA certificate?

Potentially affected

Apply this review to the BYOCA deployment model, not a new cloud-only root. Identify the private signing hierarchy, target device platforms, and systems that will accept the resulting client certificates.

DSE recommendation

Have the PKI owner produce a chain inventory before handing the signed request back to the Intune operator.

Source facts

Cloud PKI BYOCA anchors a cloud issuing CA in an existing private CA hierarchy. Enabling that issuer requires its signed certificate and the complete chain of the private signing CA. Intune requires trusted certificate profiles for every CA in that private hierarchy on each target platform. The downloaded BYOCA issuing certificate must also be installed on all relying parties. Microsoft Learn.

Applicability

Apply this review to the BYOCA deployment model, not a new cloud-only root. Identify the private signing hierarchy, target device platforms, and systems that will accept the resulting client certificates.

DSE recommendation

Have the PKI owner produce a chain inventory before handing the signed request back to the Intune operator. Match each required public certificate to a named profile or relying-party deployment owner. Compare certificate identities with the approved hierarchy and keep signing-key material out of this handoff. Treat a successful certificate upload as one checkpoint, not the entire acceptance decision.

Verification

Check the issuer state after uploading the signed certificate and chain. On an approved pilot, confirm that the intended trust profiles arrived and inspect the issued certificate path. Then exercise the actual certificate-authenticated service with its owner. Stop expansion if the endpoint and relying party disagree about the intended issuer or trust anchor; retain sanitized chain and test evidence.

Official references

Microsoft Learn: Bring your own certificate authority with Cloud PKI.

Primary reference

Review the official source

Bring your own certificate authority with Cloud PKI - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE