# Check the user certificate store when Cloud Apps device identification does not prompt

> Where must a client certificate be installed for the documented Cloud Apps browser device-identification path?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-365-check-the-user-certificate-store-when-cloud-apps-device-identification-does-not/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:51+00:00
- Modified: 2026-09-10T02:01:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Where must a client certificate be installed for the documented Cloud Apps browser device-identification path?

## Potentially affected

Defender for Cloud Apps reverse-proxy sessions using client certificates to identify managed devices.

## DSE recommendation

Trace the certificate from its signing CA to the user's browser store before changing the access policy.

## Article

## Source facts

For certificate-based device identification, Defender for Cloud Apps uses an uploaded root or intermediate CA certificate in PEM form. Microsoft’s troubleshooting requires the client certificate in PKCS #12 format in the user’s store, not the device store. Firefox additionally needs it in its own certificate store; iOS testing uses Safari. When certificate revocation checking is required, a certificate without a CRL endpoint prevents connection through this managed-device path. Proxy troubleshooting excludes Edge in-browser protection sessions. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-cloud-apps/troubleshooting-proxy).

## Applicability

Verify that the session actually uses the reverse-proxy path and that the intended policy tests the Valid client certificate device tag. Identify the browser, user profile, signing CA and presented certificate. Check the documented browser and identity-provider prerequisites before treating an absent prompt as a certificate failure.

## DSE recommendation

Trace the certificate from its signing CA to the user’s browser store before changing the access policy. Have the certificate owner confirm the trust chain and required revocation information without exporting private keys into a support ticket. Check the correct user’s store and the browser-specific requirement. Do not disable revocation checking or exempt the device merely to suppress the symptom.

## Verification

Restart the authorized test browser session and observe whether the expected certificate is offered. Then inspect the resulting Cloud Apps activity’s device tag and matched policy. Record an authentication success separately from a correct managed-device classification. If the prompt remains absent, preserve browser, operating-system and certificate-location details for support, excluding private material and unnecessary user data.

## Official references

[Microsoft Learn: Troubleshooting access and session controls for admin users](https://learn.microsoft.com/en-us/defender-cloud-apps/troubleshooting-proxy). Source reviewed September 9, 2026.

## Primary reference

- Name: Troubleshoot access and session controls for admins - Microsoft Defender for Cloud Apps | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-cloud-apps/troubleshooting-proxy
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check the user certificate store when Cloud Apps device identification does not prompt,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-365-check-the-user-certificate-store-when-cloud-apps-device-identification-does-not/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
