GuideInformationCybersecurityIT

Check the user certificate store when Cloud Apps device identification does not prompt

Where must a client certificate be installed for the documented Cloud Apps browser device-identification path?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Where must a client certificate be installed for the documented Cloud Apps browser device-identification path?

Potentially affected

Defender for Cloud Apps reverse-proxy sessions using client certificates to identify managed devices.

DSE recommendation

Trace the certificate from its signing CA to the user's browser store before changing the access policy.

Source facts

For certificate-based device identification, Defender for Cloud Apps uses an uploaded root or intermediate CA certificate in PEM form. Microsoft’s troubleshooting requires the client certificate in PKCS #12 format in the user’s store, not the device store. Firefox additionally needs it in its own certificate store; iOS testing uses Safari. When certificate revocation checking is required, a certificate without a CRL endpoint prevents connection through this managed-device path. Proxy troubleshooting excludes Edge in-browser protection sessions. Microsoft Learn.

Applicability

Verify that the session actually uses the reverse-proxy path and that the intended policy tests the Valid client certificate device tag. Identify the browser, user profile, signing CA and presented certificate. Check the documented browser and identity-provider prerequisites before treating an absent prompt as a certificate failure.

DSE recommendation

Trace the certificate from its signing CA to the user’s browser store before changing the access policy. Have the certificate owner confirm the trust chain and required revocation information without exporting private keys into a support ticket. Check the correct user’s store and the browser-specific requirement. Do not disable revocation checking or exempt the device merely to suppress the symptom.

Verification

Restart the authorized test browser session and observe whether the expected certificate is offered. Then inspect the resulting Cloud Apps activity’s device tag and matched policy. Record an authentication success separately from a correct managed-device classification. If the prompt remains absent, preserve browser, operating-system and certificate-location details for support, excluding private material and unnecessary user data.

Official references

Microsoft Learn: Troubleshooting access and session controls for admin users. Source reviewed September 9, 2026.

Primary reference

Review the official source

Troubleshoot access and session controls for admins - Microsoft Defender for Cloud Apps | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE