# Give every eligible Intune PKCS connector access to all configured CAs

> Can an administrator pin each Intune PKCS request to a preferred certificate connector?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:11+00:00
- Modified: 2026-09-10T01:40:03+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Can an administrator pin each Intune PKCS request to a preferred certificate connector?

## Potentially affected

Apply this check when adding, replacing, or segmenting current Certificate Connector for Microsoft Intune instances. Inventory enabled features per instance; do not assume a connector's name establishes request affinity.

## DSE recommendation

Review the connector fleet as a shared request-processing pool before claiming redundancy.

## Article

## Source facts

Any Intune certificate connector with PKCS enabled can retrieve pending PKCS requests, process imported certificates, and handle revocation. Microsoft does not allow administrators to select which eligible connector handles a particular request. Consequently, each PKCS-enabled connector needs equivalent permissions and connectivity to every CA named in the PKCS profiles. Each connector instance also needs access to the private key protecting uploaded PFX-file passwords. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/fundamentals/certificates/connector/overview).

## Applicability

Apply this check when adding, replacing, or segmenting current Certificate Connector for Microsoft Intune instances. Inventory enabled features per instance; do not assume a connector’s name establishes request affinity.

## DSE recommendation

Review the connector fleet as a shared request-processing pool before claiming redundancy. Build a connector-to-CA permission and reachability matrix, and have the PKI owner approve every required path. Include protected access to imported-certificate key material where that workload is used. Treat a connector that can process only a subset of the configured PKCS authorities as an unresolved design issue, rather than relying on a preferred server to win requests.

## Verification

Use approved test profiles for each configured CA and correlate the resulting requests with connector logs. During a controlled redundancy exercise, verify issuance and the required lifecycle operations through the remaining eligible instances. Preserve identities, feature configuration, and outcomes without exporting private keys. Resolve inconsistent permissions before introducing additional connector capacity.

## Official references

[Microsoft Learn: Overview of Certificate Connector for Microsoft Intune](https://learn.microsoft.com/en-us/intune/fundamentals/certificates/connector/overview).

## Primary reference

- Name: Overview of Certificate Connector for Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/fundamentals/certificates/connector/overview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Give every eligible Intune PKCS connector access to all configured CAs,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-345-give-every-eligible-intune-pkcs-connector-access-to-all-configured-cas/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
