# Separate pausing a Cloud PKI issuer from permanently retiring it

> Is the intended Cloud PKI action a temporary issuance stop or irreversible decommissioning?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:52+00:00
- Modified: 2026-09-10T01:40:02+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Is the intended Cloud PKI action a temporary issuance stop or irreversible decommissioning?

## Potentially affected

Use this review for an explicitly approved Cloud PKI decommissioning decision. Identify the exact CA and its issued certificates before selecting any lifecycle action.

## DSE recommendation

Separate the request to stop new issuance from authorization to invalidate existing credentials.

## Article

## Source facts

Pausing a Cloud PKI issuing CA stops leaf issuance but keeps revocation-list and AIA responses available. The pause can be reversed. Revocation and deletion cannot be undone: active leaf certificates must be revoked before their issuer, and an anchored issuing CA must be deleted before its root. Microsoft says issuer revocation ends authentication of its existing leaf certificates. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/cloud-pki/delete-ca).

## Applicability

Use this review for an explicitly approved Cloud PKI decommissioning decision. Identify the exact CA and its issued certificates before selecting any lifecycle action.

## DSE recommendation

Separate the request to stop new issuance from authorization to invalidate existing credentials. Map the affected certificate users and relying services, and require their owners to accept the replacement path before revocation. Record whether the proposal is a reversible pause or permanent retirement. Do not run the source’s bulk-revocation example merely to clean up a crowded console.

## Verification

For an approved pause, confirm the intended CA’s status and compare the observed issuance behavior with the agreed stop condition. Before a permanent step, reconcile active leaf certificates and dependent issuers with the retirement inventory. Use a nonproduction rehearsal for the planned order and replacement authentication. Retain approval and final state evidence outside the disappearing CA object; a successful deletion is not proof that dependent services remain usable.

## Official references

[Microsoft Learn: Delete issued PKI certificates with Microsoft Intune](https://learn.microsoft.com/en-us/intune/cloud-pki/delete-ca).

## Primary reference

- Name: Delete issued PKI certificates with Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/cloud-pki/delete-ca
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate pausing a Cloud PKI issuer from permanently retiring it,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-304-separate-pausing-a-cloud-pki-issuer-from-permanently-retiring-it/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
