Microsoft Cloud PKI: What It Covers, Costs, and Where It Stops
Blog post from Infisical
Microsoft Cloud PKI is a Microsoft Intune-hosted, two-tier certificate authority that issues SCEP-based certificates to enrolled Android, iOS/iPadOS, macOS, and Windows devices for uses such as Wi-Fi, VPN, and device authentication, removing the need for on-premises AD CS, NDES, and the Intune certificate connector. Added to Microsoft 365 E5 in July 2026 and otherwise sold as a per-user add-on, it provides managed CA hierarchy, Azure Managed HSM-backed keys for licensed production deployments, certificate revocation lists, AIA endpoints, and limited reporting, while allowing issuing CAs to be anchored to existing external roots. Its scope is restricted to Intune-managed devices and SCEP, excluding Linux, servers, unmanaged endpoints, many network and IoT devices, and issuance protocols such as ACME and EST; it also has CRL-only revocation, a three-CA tenant limit, and reporting constraints. The text argues that Cloud PKI is effective for organizations focused solely on Intune device certificates but cannot centralize broader certificate discovery, issuance, renewal, and automation needs, particularly as public TLS certificate lifetimes shorten. It presents Infisical Certificate Management as an alternative or complementary platform that can integrate with Intune while supporting additional protocols, infrastructure types, certificate discovery, external certificate authorities, and synchronization with services such as AWS Certificate Manager, Azure Key Vault, and Cloudflare.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Kubernetes | 2 | 956 | 75 | 30 | -73% |
| Secrets Management | 2 | 451 | 99 | 43 | -80% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.