# Preserve older S/MIME decryption keys when importing replacement certificates

> Why can a newly imported S/MIME certificate leave older mail unreadable?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:02+00:00
- Modified: 2026-09-10T02:04:57+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Why can a newly imported S/MIME certificate leave older mail unreadable?

## Potentially affected

Use this review for Intune imported-PKCS S/MIME encryption delivery, not merely for a mail-signing certificate. Identify the user's required devices and the older encrypted messages that must remain accessible.

## DSE recommendation

Make historical mail decryption an explicit acceptance test for certificate replacement.

## Article

## Source facts

S/MIME mail decryption requires the private key associated with the certificate used to encrypt that message. Microsoft’s imported-PKCS guidance therefore calls for preserving earlier certificates when older messages must remain readable, while importing a replacement before the current certificate expires. Ordinary SCEP and PKCS profiles issue different certificates per device, so they cannot supply the same encryption certificate across a user’s devices for this purpose. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-configuration/certificates/imported-pfx-profiles).

## Applicability

Use this review for Intune imported-PKCS S/MIME encryption delivery, not merely for a mail-signing certificate. Identify the user’s required devices and the older encrypted messages that must remain accessible.

## DSE recommendation

Make historical mail decryption an explicit acceptance test for certificate replacement. Ask the mail and PKI owners to map retained encryption certificates to the periods of mail they protect. Keep authorized key custody and device delivery separate from routine certificate cleanup. Do not delete older material solely because the newest certificate imports successfully, and do not copy private keys into ordinary support tickets.

## Verification

With an authorized test account, read representative messages encrypted before and after replacement on each required device. Confirm the intended certificate and private-key availability through protected administrative inspection. Test a replacement device as a separate recovery case. Record results and any missing history before approving retirement of older encryption material.

## Official references

[Microsoft Learn: Use imported PFX certificates in Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-configuration/certificates/imported-pfx-profiles).

## Primary reference

- Name: Use imported PFX certificates in Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-configuration/certificates/imported-pfx-profiles
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Preserve older S/MIME decryption keys when importing replacement certificates,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
