What you need to know
Why does Intune PKCS delivery require an exportable template even though the device key is marked nonexportable?
Potentially affected
Review this distinction when approving a PKCS template or investigating a failed certificate delivery. Identify the connector-generated credential path rather than importing assumptions from a device-generated SCEP key.
DSE recommendation
Document the temporary delivery requirement and the intended installed-key property as separate security decisions.
Source facts
For Intune PKCS delivery, the private key is generated on the certificate-connector server, not on the receiving device. The CA template must permit export so the connector can package the certificate as PFX and deliver it to the device. Once installed on the device, the private key is marked nonexportable. Microsoft Learn.
Applicability
Review this distinction when approving a PKCS template or investigating a failed certificate delivery. Identify the connector-generated credential path rather than importing assumptions from a device-generated SCEP key.
DSE recommendation
Document the temporary delivery requirement and the intended installed-key property as separate security decisions. Ask the PKI owner to review the exact published template and its authorized connector accounts. Do not broaden export permissions on unrelated templates to solve one deployment problem. Include the connector host in the key-handling review instead of treating the device’s final setting as a description of the whole issuance path.
Verification
Issue a controlled test certificate through the approved PKCS profile. Confirm delivery through the intended template. Inspect the installed key property only on a platform exposing it through an authorized method. Android Enterprise does not display PKCS-profile certificates on the device; Microsoft directs administrators to the profile status in Intune to confirm deployment. Microsoft Learn. Correlate the issuance record with the test identity and connector operation. Keep the evidence focused on configuration and results; do not export a production private key merely to demonstrate the distinction.
Official references
Review the official source
Use a PKCS certificate profile to provision devices with certificates in Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE