Do you still need a traditional PKI? Introducing Microsoft Cloud PKI

There’s not many of the E3/E5 inclusions left to delve into now, but this is a biggie. For years, Microsoft PKI has been regarded as necessary infrastructure, but it was always locked away within Intune Suite, for which I don’t feel the uptake was quite there. But now, with Cloud PKI included in E5, we should hopefully see the usage of Cloud PKI grow, and quite quickly too, I’d imagine.

If you’ve ever deployed Wi-Fi certificates, VPN authentication or certificate-based device authentication, chances are you’ve also spent time maintaining Active Directory Certificate Services. If you’ve ever tried to deploy certificates in a modern way, using Intune and the likes of NDES, you’ll know how much fun it can be. The fun goes away with Cloud PKI, and it genuinely becomes FUN.

What is Cloud PKI?

Cloud PKI provides a cloud-hosted public key infrastructure designed specifically for modern management scenarios.

Integrated directly with Microsoft Intune, it allows administrators to issue certificates without maintaining traditional Certificate Authorities or supporting infrastructure.

How does it compare?

Microsoft Cloud PKI is a fully managed certificate authority service built directly into Microsoft Intune.

Rather than deploying and maintaining traditional PKI infrastructure, administrators can create Root and Issuing Certification Authorities directly within the Intune admin centre. Microsoft manages the underlying infrastructure while administrators continue to control certificate issuance, revocation and policy. The service supports certificate lifecycle management across Windows, macOS, iOS/iPadOS and Android.

Certificates can be automatically issued to Intune-managed devices using standard SCEP certificate profiles, making deployment almost entirely hands-off.

Products such as SCEPman and EJBCA also offer mature cloud-first alternatives.

Where Cloud PKI differentiates itself is integration.

Certificate templates, deployment, renewal and revocation become part of the same Intune management experience administrators already use every day.

Why has PKI traditionally been difficult?

Many organisations still operate Microsoft ADCS servers that were installed years ago and have simply been left running. While they generally work well, they also introduce several challenges:

  • Certificate Authority servers require patching and maintenance.
  • NDES and Intune Certificate Connectors introduce additional infrastructure.
  • High availability requires multiple servers.
  • Certificate renewal can become operationally complex.
  • Disaster recovery planning is often overlooked.
  • PKI expertise is increasingly difficult to find.

For organisations pursuing cloud-native endpoint management, traditional PKI has often been the final dependency preventing the complete removal of on-premises infrastructure.

Cloud PKI addresses exactly this problem.

Typical Use Cases

Cloud PKI isn’t designed to replace every enterprise PKI scenario overnight. Instead, it focuses on the certificate requirements most commonly associated with endpoint management. These include:

Certificate-based Wi-Fi Authentication

Deploy unique device certificates for secure 802.1X wireless authentication without relying on passwords.

Always On VPN

Automatically provision VPN certificates, allowing seamless authentication without user interaction.

Device Identity

Issue certificates to establish trusted device identity for enterprise applications and services.

Certificate-Based Authentication (CBA)

Cloud PKI integrates with Microsoft Entra certificate-based authentication, supporting phishing-resistant authentication journeys and reducing reliance on passwords.

No More Intune Certificate Connector

One of the biggest operational wins is what disappears. Traditional Intune certificate deployments typically require:

  • Active Directory Certificate Services
  • NDES
  • Intune Certificate Connector
  • Firewall rules
  • Service accounts
  • Certificate template management

Cloud PKI removes almost all of this. There are:

  • No Certificate Connectors
  • No NDES servers
  • No CA servers to maintain
  • No Azure infrastructure to build
  • No VPN back into on-premises PKI

Provisioning a new issuing CA can take minutes rather than days or weeks.

Is on-premises PKI dead?

Absolutely not. Large enterprises still rely on internal PKI for:

  • Smart card authentication
  • Internal web services
  • Code signing
  • Legacy applications
  • Active Directory integrations

Cloud PKI isn’t designed to replace every certificate scenario. Instead, it dramatically simplifies the most common endpoint management use cases.

What does this mean for third-party vendors?

The inclusion of Cloud PKI within Microsoft 365 E5 inevitably changes the market. Products such as SCEPman and EJBCA have historically filled an important gap by simplifying cloud certificate management. For organisations already paying for Microsoft 365 E5, many of these capabilities are now available without additional licensing costs.

That doesn’t necessarily make third-party products obsolete, as the third-party offerings may still offer advanced scenarios, broader MDM support, richer reporting or specialised integrations but, as per my last few articles, it does raise the question of whether another product is still necessary for organisations standardised on Intune.

My thoughts

Microsoft has steadily been removing the remaining barriers to fully cloud-native endpoint management. With Autopilot replacing imaging, Autopatch and WUFB replacing WSUS, Enterprise App Management simplifying application packaging, Endpoint Privilege Management replacing local administrator rights, and now Cloud PKI removing traditional certificate infrastructure, the Microsoft endpoint stack is becoming increasingly self-contained.

For organisations already licensed with Microsoft 365 E5, Cloud PKI is arguably one of the most significant additions in recent years.

It simplifies certificate management, reduces infrastructure, removes operational overhead, and makes certificate-based security accessible to organisations that previously considered PKI too complex to deploy.

If you’re already planning a move away from on-premises infrastructure, Cloud PKI is well worth adding to your modern workplace roadmap.

James avatar

Leave a Reply

Your email address will not be published. Required fields are marked *