Public key infrastructure, the certificate authorities and procedures that issue certificates. Certificate-based authentication cannot work without it.
Also called public key infrastructure.
In the Ultra Transcenders books
Each book explains PKI in context, with comparison tables and the common traps.
Terms in this definition
- Certificate
Key Vault object holding an X.509 certificate, whose associated key and secret are managed alongside it.
- Certificate-based authentication
Lets people authenticate to Microsoft Entra by presenting an X.509 certificate from your organisation's PKI. Scoped to a group, it becomes an extra option, can count as passwordless MFA and doesn't stop anyone using other methods.
Related terms
- Certificate trust
With this Windows Hello for Business model, AD FS acts as registration authority while an enterprise PKI hands users their sign-in certificates. Its hybrid form depends on AD FS federation, and cloud Kerberos trust is now Microsoft's preferred choice.
- Cloud Kerberos trust
Microsoft's preferred model for hybrid Windows Hello for Business. Microsoft Entra Kerberos hands out a partial ticket-granting ticket, a domain controller swaps it for a complete one, and there is no need for PKI or synchronising keys.
- PKI-based trust store
The recommended trust store for certificate-based authentication, holding each PKI's CAs in its own container (a maximum of 250 CAs at 8 KB apiece) and supporting issuer hints. Privileged Authentication Administrators manage it, and uploading a PKI in bulk needs P1 or P2.
- Root CA
Sits at the top of a PKI as the ultimate source of trust. Microsoft Cloud PKI uses a two-tier design in which it signs the issuing CAs, with a lifetime anywhere between 5 and 25 years.