GuideInformationBusiness ContinuityIT

Separate pausing a Cloud PKI issuer from permanently retiring it

Is the intended Cloud PKI action a temporary issuance stop or irreversible decommissioning?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

Is the intended Cloud PKI action a temporary issuance stop or irreversible decommissioning?

Potentially affected

Use this review for an explicitly approved Cloud PKI decommissioning decision. Identify the exact CA and its issued certificates before selecting any lifecycle action.

DSE recommendation

Separate the request to stop new issuance from authorization to invalidate existing credentials.

Source facts

Pausing a Cloud PKI issuing CA stops leaf issuance but keeps revocation-list and AIA responses available. The pause can be reversed. Revocation and deletion cannot be undone: active leaf certificates must be revoked before their issuer, and an anchored issuing CA must be deleted before its root. Microsoft says issuer revocation ends authentication of its existing leaf certificates. Microsoft Learn.

Applicability

Use this review for an explicitly approved Cloud PKI decommissioning decision. Identify the exact CA and its issued certificates before selecting any lifecycle action.

DSE recommendation

Separate the request to stop new issuance from authorization to invalidate existing credentials. Map the affected certificate users and relying services, and require their owners to accept the replacement path before revocation. Record whether the proposal is a reversible pause or permanent retirement. Do not run the source’s bulk-revocation example merely to clean up a crowded console.

Verification

For an approved pause, confirm the intended CA’s status and compare the observed issuance behavior with the agreed stop condition. Before a permanent step, reconcile active leaf certificates and dependent issuers with the retirement inventory. Use a nonproduction rehearsal for the planned order and replacement authentication. Retain approval and final state evidence outside the disappearing CA object; a successful deletion is not proof that dependent services remain usable.

Official references

Microsoft Learn: Delete issued PKI certificates with Microsoft Intune.

Primary reference

Review the official source

Delete issued PKI certificates with Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE