# Treat derived-credential issuer recreation as a credential migration

> Can deleting and re-adding the same Intune derived-credential issuer preserve existing device credentials?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:34+00:00
- Modified: 2026-09-10T02:04:58+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

Can deleting and re-adding the same Intune derived-credential issuer preserve existing device credentials?

## Potentially affected

Apply this change-impact check before deleting a derived-credential issuer as a troubleshooting step. Inventory the profiles, supported device populations, and authentication workflows that depend on it.

## DSE recommendation

Plan issuer replacement as a coordinated credential transition with user assistance and application-owner participation.

## Article

## Source facts

An Intune tenant supports only one derived-credential issuer at a time. Deleting an issuer invalidates credentials previously obtained through it, even if the same issuer is immediately recreated. Profiles using derived credentials must then be edited to trigger an update, and device users must request new credentials. Restoring the same issuer does not remove either requirement. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-security/certificates/derived-credentials).

## Applicability

Apply this change-impact check before deleting a derived-credential issuer as a troubleshooting step. Inventory the profiles, supported device populations, and authentication workflows that depend on it.

## DSE recommendation

Plan issuer replacement as a coordinated credential transition with user assistance and application-owner participation. Preserve the configuration inventory, but do not label recreation of the old issuer a credential-preserving rollback. Arrange an approved alternative support path and clear instructions for obtaining the new credential before any disruptive change.

## Verification

In an authorized test arrangement, follow profile update and new-credential enrollment through the required application or network authentication. Record which profiles and users have completed the transition and which still require assistance. Verify the actual credential in use rather than accepting the reappearance of the issuer name in the portal as recovery. Keep private credential material outside general change records.

## Official references

[Microsoft Learn: Use derived credentials for mobile devices with Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-security/certificates/derived-credentials).

## Primary reference

- Name: Use derived credentials for mobile devices with Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-security/certificates/derived-credentials
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Treat derived-credential issuer recreation as a credential migration,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-442-treat-derived-credential-issuer-recreation-as-a-credential-migration/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
