GuideInformationBusiness ContinuityIT

Separate PKCS template export permission from the installed device key

Why does Intune PKCS delivery require an exportable template even though the device key is marked nonexportable?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

Why does Intune PKCS delivery require an exportable template even though the device key is marked nonexportable?

Potentially affected

Review this distinction when approving a PKCS template or investigating a failed certificate delivery. Identify the connector-generated credential path rather than importing assumptions from a device-generated SCEP key.

DSE recommendation

Document the temporary delivery requirement and the intended installed-key property as separate security decisions.

Source facts

For Intune PKCS delivery, the private key is generated on the certificate-connector server, not on the receiving device. The CA template must permit export so the connector can package the certificate as PFX and deliver it to the device. Once installed on the device, the private key is marked nonexportable. Microsoft Learn.

Applicability

Review this distinction when approving a PKCS template or investigating a failed certificate delivery. Identify the connector-generated credential path rather than importing assumptions from a device-generated SCEP key.

DSE recommendation

Document the temporary delivery requirement and the intended installed-key property as separate security decisions. Ask the PKI owner to review the exact published template and its authorized connector accounts. Do not broaden export permissions on unrelated templates to solve one deployment problem. Include the connector host in the key-handling review instead of treating the device’s final setting as a description of the whole issuance path.

Verification

Issue a controlled test certificate through the approved PKCS profile. Confirm delivery through the intended template. Inspect the installed key property only on a platform exposing it through an authorized method. Android Enterprise does not display PKCS-profile certificates on the device; Microsoft directs administrators to the profile status in Intune to confirm deployment. Microsoft Learn. Correlate the issuance record with the test identity and connector operation. Keep the evidence focused on configuration and results; do not export a production private key merely to demonstrate the distinction.

Official references

Microsoft Learn: Use a PKCS certificate profile to provision devices with certificates in Microsoft Intune.

Primary reference

Review the official source

Use a PKCS certificate profile to provision devices with certificates in Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE