An Intune Suite service that hosts root and issuing CAs, along with their AIA and CRL endpoints, in the cloud. It issues SCEP certificates straight to Intune-managed devices, so neither a certificate connector nor NDES is needed.
Also called Microsoft Cloud PKI.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Cloud PKI in context, with comparison tables and the common traps.
Terms in this definition
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- AIA
A certificate extension pointing to where a CA's parent certificates can be fetched. Microsoft Cloud PKI provides an AIA endpoint per issuing CA, and that endpoint, like the CRL, keeps responding even while the CA is paused.
- CRL
Certificate revocation list: a CA publishes the certificates it has withdrawn at a CRL distribution point. Certificate-based authentication downloads that list and rejects any revoked user certificate; if there is no CRL, no revocation check happens unless validation is set as required.
- SCEP
A protocol in which a device creates its own private key and asks for a certificate. In Intune, SCEP profiles depend on either Microsoft Cloud PKI or NDES alongside the Certificate Connector.
- Certificate
Key Vault object holding an X.509 certificate, whose associated key and secret are managed alongside it.
- NDES
Network Device Enrollment Service. Part of AD CS, it processes SCEP certificate requests for a Microsoft certification authority, so Intune SCEP profiles using such a CA depend on it as well as on the Certificate Connector.
Related terms
- BYOCA
Lets you chain a cloud issuing CA in Microsoft Cloud PKI to an existing private CA, AD CS for instance; that private CA signs the CSR that Intune generates.
- Issuing CA
Devices get their certificates from this kind of certification authority. With Microsoft Cloud PKI, its chain of trust leads back either to a Cloud PKI root or to a CA you already own (bring your own CA, or BYOCA).
- Microsoft Intune Suite
Sits on top of Plan 1 and contains everything in Plan 2, plus Microsoft Cloud PKI, Enterprise Application Management and Endpoint Privilege Management. Microsoft 365 E7 and E5 have included the complete bundle since July 2026.
- Root CA
Sits at the top of a PKI as the ultimate source of trust. Microsoft Cloud PKI uses a two-tier design in which it signs the issuing CAs, with a lifetime anywhere between 5 and 25 years.