Pki Design

Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments. Covers CA strategy (offline root + issuing CAs, AD CS vs managed/third-party vs public CA), Azure Key Vault certificates, HSM key protection, Entra certificate-based authentication (CBA), certificate lifecycle (issuance, renewal, rotation, revocation), and Intune SCEP/PKCS distribution. WHEN: PKI design, certificate authority, root CA offline, issuing CA, certificate management, Key Vault certificates, certificate-based authentication, CBA, certificate lifecycle, issue and rotate certificates, mTLS certificates, code signing, CRL OCSP, certificate expiry, certificate rotation, AD CS, HSM, Managed HSM. DO NOT USE for Entra ID identity model (use entra-id) or Key Vault secrets/keys only (use azure-key-vault).

vinayaklatthe Updated

File contents

vinayaklatthe/microsoft-security-skills/tree/main/skills/pki-design commit b626e48e4d

Frequently asked questions

npx skillmds@latest add vinayaklatthe/pki-design