← Previous day

Next day →
Day in brief

Cloud PKI CA expiration now has a concrete replacement runbook

New Cloud PKI guidance explains how to avoid certificate-issuance disruption when an issuing CA approaches expiration. Endpoint Privilege Management documentation also makes the child-process elevation choices and their security implications more explicit.

  • If an issuing CA expires, profiles using it cannot issue new certificates, risking Wi-Fi, VPN, email, corporate-resource, and certificate-authentication failures. Microsoft says administrators must create a new issuing CA and replace the old SCEP URI in each affected profile; Microsoft cannot do this automatically.

  • Endpoint Privilege Management · Device security
    EPM explains child-process elevation behavior and the safer default

    Elevation rules can require each child process to meet its own rule, deny all child elevation, or allow children to inherit elevation. The documentation warns that inherited elevation skips child rule and deny-rule evaluation, and recommends avoiding broad rules for shells and script engines.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

4 updates

1

Epm Elevation Rules

Updated

Updated Microsoft Intune documentation in intune/intune-service/protect/epm-elevation-rules.md.

3

Renew Ca

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/renew-ca.md.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Email signup will appear here once the Kit form is configured. Until then, use the daily RSS feed.