Set up Microsoft Cloud PKI

Microsoft Cloud PKI is a cloud certificate authority included with the Intune Suite. It issues certificates to Intune-enrolled devices over SCEP without a server of your own, which makes it a reasonable default if you manage devices with Intune and have no existing PKI.

Before you begin

You need an Intune tenant with Cloud PKI licensed, and permission to create certificate authorities in the Intune admin center.

Create the certificate authorities

  1. In the Intune admin center, go to Tenant administration → Cloud PKI and select Create.
  2. Create a root CA named Firezone Root. Include Client Authentication in its Extended Key Usages.
  3. Create an issuing CA named Firezone Issuer, select Issuing CA as its type, and select Firezone Root as its root CA. Include Client Authentication in its Extended Key Usages.
  4. Open each CA's Properties page and download its public certificate.

Include Client Authentication in the Extended Key Usages of both CAs. Firezone rejects a certificate that does not carry it, and the setting cannot be changed after a CA is created.

You now have two public certificates and a SCEP URI. The Intune guides refer to these CAs by the names above when creating trusted certificate and SCEP profiles.

Next step

Add both CA certificates to Firezone as trust anchors, in step 2 of Set up Device Trust.

See Microsoft's Cloud PKI configuration guide for the complete CA creation workflow.


Need help? See all support options.