Certificate revocation list: a CA publishes the certificates it has withdrawn at a CRL distribution point. Certificate-based authentication downloads that list and rejects any revoked user certificate; if there is no CRL, no revocation check happens unless validation is set as required.
Also called certificate revocation list.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains CRL in context, with comparison tables and the common traps.
Terms in this definition
- Certificate-based authentication
Lets people authenticate to Microsoft Entra by presenting an X.509 certificate from your organisation's PKI. Scoped to a group, it becomes an extra option, can count as passwordless MFA and doesn't stop anyone using other methods.
- List
Permission on Key Vault secrets allowing a caller to enumerate those in a vault, though their values are not returned.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Certificate
Key Vault object holding an X.509 certificate, whose associated key and secret are managed alongside it.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
Related terms
- AIA
A certificate extension pointing to where a CA's parent certificates can be fetched. Microsoft Cloud PKI provides an AIA endpoint per issuing CA, and that endpoint, like the CRL, keeps responding even while the CA is paused.
- Cloud PKI
An Intune Suite service that hosts root and issuing CAs, along with their AIA and CRL endpoints, in the cloud. It issues SCEP certificates straight to Intune-managed devices, so neither a certificate connector nor NDES is needed.
- OCSP
The Online Certificate Status Protocol for checking whether a certificate has been revoked. Microsoft Entra certificate-based authentication does not use it, relying instead on a single CRL distribution point for each CA.