Testing Cloud PKI against Windows Web Server

Pavel yannara Mirochnitchenko 12,386 Reputation points MVP
2024-04-16T10:58:50.44+00:00

I am evaluating Intune Cloud PKI solution and I want to test the certification usage with IIS build on Windows Server. The Server is not member of Active Directory, so I downloaded Root and Issuing certificates as files and imported them into the Windows Server. The problem is, when I try to add IIS binding for https, and selecting certificate, that certificates from Intune Root and Issuing are not viewed. Also when I created Root CA, I didn't see Web server purpose. Only Client and Server.

User's image

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
370 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 45,571 Reputation points Microsoft Vendor
    2024-04-17T05:47:09.44+00:00

    @Pavel yannara Mirochnitchenko, Thanks for posting in Q&A. In Fact, Microsoft Cloud PKI to issue certificates for Intune-managed devices.

    https://video2.skills-academy.com/en-us/mem/intune/protect/microsoft-cloud-pki-overview

    Currently, windows server cannot managed by Intune yet. So we can't deploy certificate to windows web server yet.

    https://video2.skills-academy.com/en-us/mem/intune/fundamentals/supported-devices-browsers

    Meanwhile, For the web server certificate which is used to enables secure communication between a web server and a web browser. The subject name needs to be the web server name or the name you used to publish out. Root CA and Issuing CA certificate is used to validate the certificate you request from the CA is valid. And it can't be used to bind with https.

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful