Devices get their certificates from this kind of certification authority. With Microsoft Cloud PKI, its chain of trust leads back either to a Cloud PKI root or to a CA you already own (bring your own CA, or BYOCA).
Also called issuing certification authority.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Issuing CA in context, with comparison tables and the common traps.
Terms in this definition
- Get
Key Vault permission on secrets that allows a single secret to be read; App Service Key Vault references need nothing beyond it.
- Cloud PKI
An Intune Suite service that hosts root and issuing CAs, along with their AIA and CRL endpoints, in the cloud. It issues SCEP certificates straight to Intune-managed devices, so neither a certificate connector nor NDES is needed.
- BYOCA
Lets you chain a cloud issuing CA in Microsoft Cloud PKI to an existing private CA, AD CS for instance; that private CA signs the CSR that Intune generates.
Related terms
- AIA
A certificate extension pointing to where a CA's parent certificates can be fetched. Microsoft Cloud PKI provides an AIA endpoint per issuing CA, and that endpoint, like the CRL, keeps responding even while the CA is paused.