GuideInformationBusiness ContinuityIT

Treat derived-credential issuer recreation as a credential migration

Can deleting and re-adding the same Intune derived-credential issuer preserve existing device credentials?

Integrated video surveillance and controlled entry at a modern commercial facility.
DSE visual intelligencePhysical securityGuide · 1 min read
Executive summary

What you need to know

Can deleting and re-adding the same Intune derived-credential issuer preserve existing device credentials?

Potentially affected

Apply this change-impact check before deleting a derived-credential issuer as a troubleshooting step. Inventory the profiles, supported device populations, and authentication workflows that depend on it.

DSE recommendation

Plan issuer replacement as a coordinated credential transition with user assistance and application-owner participation.

Source facts

An Intune tenant supports only one derived-credential issuer at a time. Deleting an issuer invalidates credentials previously obtained through it, even if the same issuer is immediately recreated. Profiles using derived credentials must then be edited to trigger an update, and device users must request new credentials. Restoring the same issuer does not remove either requirement. Microsoft Learn.

Applicability

Apply this change-impact check before deleting a derived-credential issuer as a troubleshooting step. Inventory the profiles, supported device populations, and authentication workflows that depend on it.

DSE recommendation

Plan issuer replacement as a coordinated credential transition with user assistance and application-owner participation. Preserve the configuration inventory, but do not label recreation of the old issuer a credential-preserving rollback. Arrange an approved alternative support path and clear instructions for obtaining the new credential before any disruptive change.

Verification

In an authorized test arrangement, follow profile update and new-credential enrollment through the required application or network authentication. Record which profiles and users have completed the transition and which still require assistance. Verify the actual credential in use rather than accepting the reappearance of the issuer name in the portal as recovery. Keep private credential material outside general change records.

Official references

Microsoft Learn: Use derived credentials for mobile devices with Microsoft Intune.

Primary reference

Review the official source

Use derived credentials for mobile devices with Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE