GuideInformationBusiness ContinuityIT

Give every eligible Intune PKCS connector access to all configured CAs

Can an administrator pin each Intune PKCS request to a preferred certificate connector?

Governed cloud identity system with connected service and lifecycle nodes.
DSE visual intelligenceIdentity & cloudGuide · 2 min read
Executive summary

What you need to know

Can an administrator pin each Intune PKCS request to a preferred certificate connector?

Potentially affected

Apply this check when adding, replacing, or segmenting current Certificate Connector for Microsoft Intune instances. Inventory enabled features per instance; do not assume a connector's name establishes request affinity.

DSE recommendation

Review the connector fleet as a shared request-processing pool before claiming redundancy.

Source facts

Any Intune certificate connector with PKCS enabled can retrieve pending PKCS requests, process imported certificates, and handle revocation. Microsoft does not allow administrators to select which eligible connector handles a particular request. Consequently, each PKCS-enabled connector needs equivalent permissions and connectivity to every CA named in the PKCS profiles. Each connector instance also needs access to the private key protecting uploaded PFX-file passwords. Microsoft Learn.

Applicability

Apply this check when adding, replacing, or segmenting current Certificate Connector for Microsoft Intune instances. Inventory enabled features per instance; do not assume a connector’s name establishes request affinity.

DSE recommendation

Review the connector fleet as a shared request-processing pool before claiming redundancy. Build a connector-to-CA permission and reachability matrix, and have the PKI owner approve every required path. Include protected access to imported-certificate key material where that workload is used. Treat a connector that can process only a subset of the configured PKCS authorities as an unresolved design issue, rather than relying on a preferred server to win requests.

Verification

Use approved test profiles for each configured CA and correlate the resulting requests with connector logs. During a controlled redundancy exercise, verify issuance and the required lifecycle operations through the remaining eligible instances. Preserve identities, feature configuration, and outcomes without exporting private keys. Resolve inconsistent permissions before introducing additional connector capacity.

Official references

Microsoft Learn: Overview of Certificate Connector for Microsoft Intune.

Primary reference

Review the official source

Overview of Certificate Connector for Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE