What you need to know
Why can a newly imported S/MIME certificate leave older mail unreadable?
Potentially affected
Use this review for Intune imported-PKCS S/MIME encryption delivery, not merely for a mail-signing certificate. Identify the user's required devices and the older encrypted messages that must remain accessible.
DSE recommendation
Make historical mail decryption an explicit acceptance test for certificate replacement.
Source facts
S/MIME mail decryption requires the private key associated with the certificate used to encrypt that message. Microsoft’s imported-PKCS guidance therefore calls for preserving earlier certificates when older messages must remain readable, while importing a replacement before the current certificate expires. Ordinary SCEP and PKCS profiles issue different certificates per device, so they cannot supply the same encryption certificate across a user’s devices for this purpose. Microsoft Learn.
Applicability
Use this review for Intune imported-PKCS S/MIME encryption delivery, not merely for a mail-signing certificate. Identify the user’s required devices and the older encrypted messages that must remain accessible.
DSE recommendation
Make historical mail decryption an explicit acceptance test for certificate replacement. Ask the mail and PKI owners to map retained encryption certificates to the periods of mail they protect. Keep authorized key custody and device delivery separate from routine certificate cleanup. Do not delete older material solely because the newest certificate imports successfully, and do not copy private keys into ordinary support tickets.
Verification
With an authorized test account, read representative messages encrypted before and after replacement on each required device. Confirm the intended certificate and private-key availability through protected administrative inspection. Test a replacement device as a separate recovery case. Record results and any missing history before approving retirement of older encryption material.
Official references
Microsoft Learn: Use imported PFX certificates in Microsoft Intune.
Review the official source
Use imported PFX certificates in Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE