[{"data":1,"prerenderedAt":580},["ShallowReactive",2],{"sc:header-data-en":3,"sc:footer-data-en":95,"post-en--posts-ecc-vs-rsa-for-intune-scep-89d2005bacf31":126,"authors_data":376,"authors_data:SCEPman Team":460,"content-en-list-7b291c2dd91a4":462},{"lang":4,"home":5,"navigation":14},"en",{"name":6,"imgLight":7,"img":8,"languages":9},"home","/products/scepman/scepman-logo-all-white.svg","/products/scepman/scepman-logo-rgb.svg",{"en":10},{"title":11,"url":12,"alt":13},"Home","/en","SCEPman",[15,19,25,31,83,89],{"name":16,"languages":17},"nav-home",{"en":18},{"title":11,"url":12},{"name":20,"languages":21},"pricing",{"en":22},{"title":23,"url":24},"Pricing","/en/pricing",{"name":26,"languages":27},"partner",{"en":28},{"title":29,"url":30},"Partner","/en/partner",{"name":32,"languages":33,"children":36},"support-hub",{"en":34},{"title":35},"Support Hub",[37,53,68],{"name":38,"children":39},"support-hub-group-1",[40,47],{"name":41,"target":42,"languages":43},"docs","_blank",{"en":44},{"title":45,"url":46},"Docs","https://docs.scepman.com/",{"name":48,"languages":49},"faq",{"en":50},{"title":51,"url":52},"FAQ","/en/faq",{"name":54,"children":55},"support-hub-group-2",[56,62],{"name":57,"target":42,"languages":58},"support-ticket",{"en":59},{"title":60,"url":61},"Support Ticket","https://support.scepman.com/support/tickets/new?ticket_form=technical_support_request_%28scepman%29",{"name":63,"target":42,"languages":64},"drop-a-question",{"en":65},{"title":66,"url":67},"Contact Sales","https://support.scepman.com/support/tickets/new?ticket_form=drop_a_question_%28scepman%29",{"name":69,"children":70},"support-hub-group-3",[71,77],{"name":72,"languages":73},"glossary",{"en":74},{"title":75,"url":76},"Glossary","/en/glossary",{"name":78,"languages":79},"blog",{"en":80},{"title":81,"url":82},"Blog","/en/blog",{"name":84,"languages":85},"events",{"en":86},{"title":87,"url":88},"Events","/en/events",{"name":90,"languages":91},"about",{"en":92},{"title":93,"url":94},"About us","/en/about-us",{"data":96},{"mail":97,"logos":98,"socials":103,"links":116},"sales@SCEPman.com",[99],{"img":100,"alt":101,"url":102},"/products/scepman/scepman-logo-yellow.svg","SCEPman Logo","/",[104,108,112],{"icon":105,"url":106,"title":107},"fa-x-twitter","https://twitter.com/scepman_","X",{"icon":109,"url":110,"title":111},"fa-youtube","https://www.youtube.com/channel/UCKnLYxlQFhzdXkDADV_Unrg","Youtube",{"icon":113,"url":114,"title":115},"fa-linkedin","https://www.linkedin.com/showcase/scepman","LinkedIn",[117,120,123],{"title":118,"url":119,"target":42},"Privacy","https://www.glueckkanja.com/en/privacy",{"title":121,"url":122,"target":42},"Imprint","https://www.glueckkanja.com/en/imprint",{"title":124,"url":125,"target":42},"Contact & Locations","https://www.glueckkanja.com/en/company/contact-and-locations",{"id":127,"title":128,"author":129,"body":131,"cta":341,"description":137,"eventid":341,"extension":342,"hideInRecent":343,"layout":344,"meta":345,"moment":348,"navigation":366,"path":368,"seo":369,"stem":370,"tags":371,"webcast":343,"__hash__":375},"content_en/posts/ecc-vs-rsa-for-intune-scep.md","ECC vs RSA for Intune Clients",[130],"SCEPman Team",{"type":132,"value":133,"toc":331},"minimal",[134,138,141,146,149,152,155,172,175,179,182,208,211,214,218,221,225,228,231,234,238,241,245,263,269,325,328],[135,136,137],"p",{},"For certificate distribution to Intune-managed clients via SCEP, SCEPman recommends RSA. As of June 2026, ECC (Elliptic Curve Cryptography) is not officially supported for this scenario.",[135,139,140],{},"The limitation is not specific to SCEPman: it comes from the SCEP protocol itself and from Microsoft Intune's SCEP certificate profile, which only lets you request RSA keys. If you need ECC for resource-constrained or battery-powered IoT devices that enroll outside of Intune (for example through SCEPman's REST API), SCEPman can operate an ECC CA, but that is a separate use case from MDM-based client distribution.",[142,143,145],"h2",{"id":144},"why-scep-is-tied-to-rsa","Why SCEP Is Tied to RSA",[135,147,148],{},"SCEP (Simple Certificate Enrollment Protocol, standardized in RFC 8894 and based on earlier drafts) protects its enrollment messages with CMS (Cryptographic Message Syntax, formerly PKCS#7). Each message is first encrypted to the recipient's public key and then signed. This encryption step is the core problem for ECC.",[135,150,151],{},"RSA can be used for both signing and encryption. ECC cannot. ECDSA exists for signing, but there is no widely adopted, standardized elliptic-curve encryption algorithm equivalent to RSA encryption. As a result, you cannot directly encrypt a CMS message to an elliptic-curve key. RFC 8894, Section 3.1 makes this explicit: it specifies that when the recipient's key is encryption capable, such as RSA, the message data is encrypted to that public key using the CMS KeyTransRecipientInfo mechanism, whereas when the key cannot perform encryption, such as DSA or ECDSA, the message data is instead encrypted using the challenge password via the CMS PasswordRecipientInfo mechanism.",[135,153,154],{},"This affects SCEP in two places:",[156,157,158,166],"ul",{},[159,160,161,165],"li",{},[162,163,164],"strong",{},"Encrypting the request to the CA key."," SCEP requires the enrollment request to be encrypted to the CA's public key. If the CA key is an ECC key, the client cannot encrypt to it directly, so an ECC CA is not directly usable for SCEP.",[159,167,168,171],{},[162,169,170],{},"Encrypting the response to the to-be-issued certificate's key."," The SCEP response containing the issued certificate is encrypted to the public key being certified. If that key is an ECC key, the CA cannot encrypt the response to it directly, so issuing an ECC end-entity certificate over SCEP is not directly possible either.",[135,173,174],{},"The password-based fallback that RFC 8894 describes for non-encryption-capable keys is effectively a different mode that almost no real-world deployment uses, and Intune does not use it. For this reason, SCEP implementations in practice enroll certificates for RSA keys only.",[142,176,178],{"id":177},"what-microsoft-intune-actually-offers","What Microsoft Intune Actually Offers",[135,180,181],{},"Even setting aside the protocol theory, the practical constraint is the Intune SCEP certificate profile. In the Intune SCEP profile there is no key type selector and no curve selector. The only key-algorithm-related settings are:",[156,183,184,190,196,202],{},[159,185,186,189],{},[162,187,188],{},"Key Storage Provider (KSP)"," (Windows only)",[159,191,192,195],{},[162,193,194],{},"Key usage"," (Digital signature and/or Key encipherment)",[159,197,198,201],{},[162,199,200],{},"Key size (bits):"," Not configured, 1024, 2048, or 4096",[159,203,204,207],{},[162,205,206],{},"Hash algorithm"," (Android and Windows)",[135,209,210],{},"These key sizes are RSA key sizes. There is no option to choose Elliptic Curve as the key type, and no option to select a NIST curve such as P-256, P-384, or P-521. The presence of the Key encipherment usage is itself an indicator that the profile targets RSA, because ECC keys cannot perform key encipherment. This holds for all client platforms (Windows, iOS/iPadOS, macOS, Android); the platform differences that exist relate only to RSA key size and key storage, not to ECC support. The 4096-bit RSA size is supported on Android (all), iOS/iPadOS 14 and later, macOS 11 and later, and Windows (all), though on Windows 4096-bit keys are supported only in the Software KSP and not in the hardware TPM or Windows Hello for Business.",[135,212,213],{},"You may come across descriptions elsewhere that suggest the Intune SCEP profile lets you select ECC and a P-256 curve. In our reading of the current Microsoft documentation, such descriptions generally refer to a given PKI back end's own capabilities rather than to the key options that the native Intune SCEP profile actually exposes.",[142,215,217],{"id":216},"what-about-workarounds","What About Workarounds?",[135,219,220],{},"Workarounds for both cases (an ECC CA and ECC end-entity certificates over SCEP) do exist at the protocol level, generally relying on the challenge-password encryption path described in RFC 8894 or on separating signing and key-agreement keys. SCEPman is able to operate an ECC CA, which is documented and used today for IoT scenarios where devices enroll via SCEPman's REST API rather than via an MDM. However, distributing ECC end-entity certificates to clients specifically over SCEP through Intune is not officially supported, is undocumented and untested by us, and is not in production use by any customer we know of. The decisive dependency is the MDM: Intune would need to support requesting an ECC key over SCEP, and as described above it currently does not. Therefore, RSA is effectively the only option for all SCEP-based certificate distribution to Intune-managed clients.",[142,222,224],{"id":223},"when-does-ecc-make-sense-with-scepman","When Does ECC Make Sense with SCEPman?",[135,226,227],{},"So where does ECC actually make sense with SCEPman? The useful scenarios are precisely the ones that do not run over the Intune SCEP client distribution path.",[135,229,230],{},"SCEPman can operate a dedicated ECC certificate authority for scenarios that do not require SCEP, supporting the elliptic curves P-256, secp256k1/P-256K, P-384 and P-521, and devices in these scenarios typically enroll through SCEPman's Enrollment REST API, which uses the EST (Enrollment over Secure Transport) protocol with Microsoft Entra ID authentication, rather than through an MDM. The classic fit is IoT and embedded devices: ECC delivers the same security strength as RSA with far smaller keys (for example, a 256-bit ECC key is comparable to a 3072-bit RSA key, and a 384-bit ECC key to a 7680-bit RSA key, per NIST SP 800-57 Part 1 Rev. 5), which means smaller certificates and signatures, faster key generation, lower CPU and memory use, less bandwidth, and notably lower battery drain on resource-constrained or battery-powered hardware. This is exactly why SCEPman supports an ECC CA that allows performance- and energy-optimized cryptographic algorithms on devices with limited computational resources or on devices relying on battery power, often combined with long certificate validity periods for long-term offline operation and convenient assembly-line enrollment via the REST API.",[135,232,233],{},"In all of these cases the common thread is the same: ECC with SCEPman is appropriate for non-Intune-SCEP enrollment paths (the REST API / EST and direct-CA scenarios for IoT, servers and other devices), and not for the standard Intune SCEP client distribution path described above, which remains tied to RSA.",[142,235,237],{"id":236},"try-scepman-for-yourself","Try SCEPman for Yourself",[135,239,240],{},"Start a 30-day trial to see how SCEPman issues and manages private CA certificates for your devices, users, and internal services, without the overhead of running your own PKI.",[242,243,244],"style",{},".trial-cta { display: inline-block; margin-bottom: 3.5rem; } .trial-cta:hover { --cta-copy-color: white !important; }",[135,246,247],{},[248,249,258],"a",{"role":250,"className":251,"dataText":256,"href":257,"target":42},"button",[252,253,254,255],"cta","btn","btn-primary","trial-cta","Start SCEPman 30-day trial","https://support.scepman.com/support/tickets/new?ticket_form=trial_request_%28scepman%29",[259,260,256],"span",{"className":261},[262],"cta__text",[142,264,268],{"id":265,"className":266},"frequently-asked-questions",[267],"faq-heading","Frequently Asked Questions",[270,271,275,285,293,301,309,317],"div",{"className":272,"style":274},[273],"faq-foldable","grid-column: content;",[276,277,278,282],"details",{},[279,280,281],"summary",{},"Can I use ECC certificates with Intune SCEP profiles?",[135,283,284],{},"No. The Intune SCEP certificate profile does not expose ECC or curve selection options. It supports only RSA key sizes (1024, 2048, 4096 bits) across all client platforms. The SCEP protocol itself also makes ECC problematic due to CMS encryption limitations, so even if Intune offered the option, most real-world SCEP implementations do not support it.",[276,286,287,290],{},[279,288,289],{},"Why can't SCEP just use a password-based fallback for ECC?",[135,291,292],{},"RFC 8894 does describe a password-based fallback for encryption when the recipient's key cannot perform encryption (like ECC keys). However, this mode is rarely implemented in practice and is not used by Intune or most MDM platforms. Relying on it would create incompatibility with mainstream SCEP clients and MDM solutions.",[276,294,295,298],{},[279,296,297],{},"Does SCEPman support ECC at all?",[135,299,300],{},"Yes, but not for Intune SCEP enrollment. SCEPman can operate a dedicated ECC CA (supporting P-256, P-384, P-521, and secp256k1) for IoT and embedded devices that enroll via SCEPman's REST API with EST and Microsoft Entra ID authentication. This is ideal for resource-constrained and battery-powered devices where ECC's efficiency matters most.",[276,302,303,306],{},[279,304,305],{},"What are the advantages of ECC for IoT devices with SCEPman?",[135,307,308],{},"ECC provides the same security strength as RSA with much smaller keys (a 256-bit ECC key is comparable to a 3072-bit RSA key). This means smaller certificates, faster key generation, lower CPU and memory use, reduced bandwidth, and significantly lower battery drain on resource-constrained or battery-powered hardware.",[276,310,311,314],{},[279,312,313],{},"If I need ECC certificates for my devices, what should I do?",[135,315,316],{},"If the devices do not enroll through Intune SCEP, you can use SCEPman's REST API with EST protocol and Microsoft Entra ID authentication to issue ECC certificates. This approach works for IoT, embedded systems, servers, and other infrastructure that benefits from ECC efficiency without the Intune SCEP constraint.",[276,318,319,322],{},[279,320,321],{},"Will Intune add ECC support to its SCEP profile in the future?",[135,323,324],{},"We are not aware of any roadmap announcements from Microsoft on ECC support for the Intune SCEP profile. Any such change would require both the MDM profile to expose ECC selection and a shift in how SCEP encryption is handled. Until then, RSA remains the only supported option for Intune SCEP-based certificate distribution.",[242,326,327],{},"\n.faq-heading {\n  margin-top: 4rem;\n  white-space: nowrap;\n}\n.tight-list p { margin-bottom: 0.25rem !important; }\n.tight-list ul { margin-top: 0 !important; }\n.faq-foldable {\n  margin-bottom: 4rem;\n}\n.faq-foldable details {\n  border-top: 1px solid rgba(0, 0, 0, 0.12);\n  padding: 0;\n}\n.faq-foldable details:last-of-type {\n  border-bottom: 1px solid rgba(0, 0, 0, 0.12);\n}\n.faq-foldable summary {\n  list-style: none;\n  cursor: pointer;\n  display: flex;\n  justify-content: space-between;\n  align-items: center;\n  gap: 1rem;\n  padding: 1rem 0;\n  font-weight: 600;\n}\n.faq-foldable summary::-webkit-details-marker {\n  display: none;\n}\n.faq-foldable summary::after {\n  content: \"▸\";\n  transition: transform 0.2s ease;\n  flex-shrink: 0;\n}\n.faq-foldable details[open] summary::after {\n  transform: rotate(90deg);\n}\n.faq-foldable details[open] summary {\n  border-bottom: none;\n  padding-bottom: 1rem;\n}\n.faq-foldable details[open] > :last-child {\n  padding-bottom: 1rem;\n}\n",[135,329,330],{},"Last updated: September 2026. All product and company names mentioned in this article, including Microsoft, Intune, Microsoft Entra ID, Azure, Windows, and the names of other vendors and products, are trademarks or registered trademarks of their respective owners. Their use here is for identification and descriptive purposes only and does not imply any affiliation with or endorsement by those owners.",{"title":332,"searchDepth":333,"depth":333,"links":334},"",2,[335,336,337,338,339,340],{"id":144,"depth":333,"text":145},{"id":177,"depth":333,"text":178},{"id":216,"depth":333,"text":217},{"id":223,"depth":333,"text":224},{"id":236,"depth":333,"text":237},{"id":265,"depth":333,"text":268},null,"md",false,"post",{"lang":4,"seoTitle":346,"titleClass":347,"date":348,"categories":349,"blogtitlepic":350,"socialimg":351,"customExcerpt":352,"keywords":353,"asideNav":354,"maxContent":366,"footer":367},"ECC vs RSA for Intune SCEP: Why RSA Is Required","h2-font-size","2026-09-23",[13],"header-scepman-ecc-vs-rsa-for-intune-clients.png","/blog/heads/header-scepman-ecc-vs-rsa-for-intune-clients.png","Intune's SCEP profile only supports RSA keys, not ECC. Learn why SCEP and CMS encryption block elliptic curve certificates, and where ECC still works with SCEPman.","ECC vs RSA Intune, Intune SCEP ECC support, SCEP RSA only, Intune SCEP certificate profile, SCEP ECC limitation, CMS encryption ECC, RFC 8894 SCEP, ECC certificate authority IoT, SCEPman ECC CA, elliptic curve MDM certificates, Intune key storage provider, why does Intune SCEP only support RSA, can you use ECC keys with Intune SCEP profile, is elliptic curve cryptography supported in SCEP, ECC certificates for IoT devices with SCEPman",{"menuItems":355},[356,358,360,362,364],{"href":357,"text":145},"#why-scep-is-tied-to-rsa",{"href":359,"text":178},"#what-microsoft-intune-actually-offers",{"href":361,"text":217},"#what-about-workarounds",{"href":363,"text":224},"#when-does-ecc-make-sense-with-scepman",{"href":365,"text":268},"#frequently-asked-questions",true,{"noMargin":366},"/posts/ecc-vs-rsa-for-intune-scep",{"title":128,"description":137},"posts/ecc-vs-rsa-for-intune-scep",[372,373,374],"SCEP","Intune","ECC vs RSA","Lr3Ls5DaakfIEBOgFqznAeK2giVDtXcL2KoQE0MpuGw",{"id":377,"extension":378,"meta":379,"stem":458,"__hash__":459},"authors_data/authors.json","json",{"path":380,"Alexander Rudolph":381,"Sophie Luna":387,"Nadine Kern":393,"Thorben Pöschus":399,"Karsten Kleinschmidt":405,"Julian Wendt":411,"Holger Bunkradt":416,"Ralf Mania":422,"Oliver Kieselbach":428,"Steffen Schwerdtfeger":434,"Christoph Hannebauer":440,"body":445,"title":457},"/authors",{"display_name":382,"avatar":383,"permalink":384,"twitter":385,"linkedin":386},"Alexander Rudolph","people/people-alexander-rudolph.png","author/alexander-rudolph/","AlexanderOnIT","rudolph-alexander",{"display_name":388,"avatar":389,"permalink":390,"twitter":391,"linkedin":392},"Sophie Luna","c_thumb,h_1600,w_1600/people/people-sophie-luna.jpg","author/sophie-luna/","glueckkanjagab","company/glueckkanja-gab",{"display_name":394,"avatar":395,"permalink":396,"twitter":397,"linkedin":398},"Nadine Kern","people/people-nadine-kern.png","author/nadine-kern/","nadineausRT","nadine-kern",{"display_name":400,"avatar":401,"permalink":402,"twitter":403,"linkedin":404},"Thorben Pöschus","people/people-thorben-poeschus.png","author/thorben-poeschus/","TPO901","thorben-pöschus-624693b7",{"display_name":406,"avatar":407,"permalink":408,"twitter":409,"linkedin":410},"Karsten Kleinschmidt","people/people-karsten-kleinschmidt.png","author/karsten-kleinschmidt/","KarstenonIT","karstenkleinschmidt",{"display_name":412,"avatar":413,"permalink":414,"linkedin":415},"Julian Wendt","people/people-julian-wendt.png","author/julian-wendt/","julian-wendt",{"display_name":417,"avatar":418,"permalink":419,"linkedin":420,"twitter":421},"Holger Bunkradt","people/people-holger-bunkradt.png","author/holger-bunkradt/","holger-bunkradt-12b5053b","hbunkradt",{"display_name":423,"avatar":424,"permalink":425,"linkedin":426,"twitter":427},"Ralf Mania","people/people-ralf-mania.png","author/ralf-mania/","ralf-mania-146a2757","RaMa1976",{"display_name":429,"avatar":430,"permalink":431,"linkedin":432,"twitter":433},"Oliver Kieselbach","people/people-oliver-kieselbach.png","author/oliver-kieselbach/","oliver-kieselbach-a4a3409","okieselbT",{"display_name":435,"avatar":436,"permalink":437,"linkedin":438,"twitter":439},"Steffen Schwerdtfeger","people/people-steffen-schwerdtfeger.png","author/steffen-schwerdtfeger/","steffen-schwerdtfeger","SteffenAtCloud",{"display_name":441,"avatar":442,"permalink":443,"twitter":391,"linkedin":392,"imageOffsetTop":444},"Dr. Christoph Hannebauer","people/people-christoph-hannebauer.png","/authors/christoph-hannebauer/","72%",{"Alexander Rudolph":446,"Sophie Luna":447,"Nadine Kern":448,"Thorben Pöschus":449,"Karsten Kleinschmidt":450,"Julian Wendt":451,"Holger Bunkradt":452,"Ralf Mania":453,"Oliver Kieselbach":454,"Steffen Schwerdtfeger":455,"Christoph Hannebauer":456},{"display_name":382,"avatar":383,"permalink":384,"twitter":385,"linkedin":386},{"display_name":388,"avatar":389,"permalink":390,"twitter":391,"linkedin":392},{"display_name":394,"avatar":395,"permalink":396,"twitter":397,"linkedin":398},{"display_name":400,"avatar":401,"permalink":402,"twitter":403,"linkedin":404},{"display_name":406,"avatar":407,"permalink":408,"twitter":409,"linkedin":410},{"display_name":412,"avatar":413,"permalink":414,"linkedin":415},{"display_name":417,"avatar":418,"permalink":419,"linkedin":420,"twitter":421},{"display_name":423,"avatar":424,"permalink":425,"linkedin":426,"twitter":427},{"display_name":429,"avatar":430,"permalink":431,"linkedin":432,"twitter":433},{"display_name":435,"avatar":436,"permalink":437,"linkedin":438,"twitter":439},{"display_name":441,"avatar":442,"permalink":443,"twitter":391,"linkedin":392,"imageOffsetTop":444},"Authors","authors","PIJJchcHqfzD5YPmn4V8YLxY6gtySOfBG5u8lTczi2w",{"id":377,"extension":378,"meta":461,"stem":458,"__hash__":459},{},{"list":463,"authors":579},[464,469,488,504,518,531,543,555,567],{"id":127,"title":128,"author":465,"cta":341,"description":137,"hideInRecent":343,"layout":344,"meta":466,"moment":348,"path":368,"stem":370,"tags":468,"webcast":343},[130],{"lang":4,"date":348,"categories":467,"blogtitlepic":350,"customExcerpt":352},[13],[372,373,374],{"id":470,"title":471,"author":472,"cta":341,"description":474,"hideInRecent":343,"layout":344,"meta":475,"moment":476,"path":480,"stem":481,"tags":482,"webcast":343},"content_en/posts/private-ca-vs-public-ca.md","Private vs Public CAs: You Might Be Using the Wrong One",[473],"Kevin Vo","To an IT team under pressure, a public Certificate Authority (CA) often looks like a hammer, and every encryption requirement looks like a nail. But using a public CA for every job is one of the most common ways to quietly break production.",{"lang":4,"date":476,"categories":477,"blogtitlepic":478,"customExcerpt":479},"2026-08-24",[13],"header-scepman-private-vs-public-ca.png","Public CA certificates lose client authentication support by March 2027. See when a private CA is required, and how SCEPman automates issuance.","/posts/private-ca-vs-public-ca","posts/private-ca-vs-public-ca",[483,484,485,486,487],"Private CA","Public CA","PKI","Client Authentication","Certificate Authority",{"id":489,"title":490,"author":491,"cta":341,"description":492,"hideInRecent":343,"layout":344,"meta":493,"moment":494,"path":498,"stem":499,"tags":500,"webcast":343},"content_en/posts/adcs-alternatives.md","Microsoft ADCS Alternatives in 2026",[130],"Microsoft Active Directory Certificate Services — also known as ADCS, ADCA, or Microsoft CA — has been the default PKI for Windows environments for years. Many organizations still rely on it for certificate issuance across users, devices, and servers.",{"lang":4,"date":494,"categories":495,"blogtitlepic":496,"customExcerpt":497},"2026-05-01",[13],"header-scepman-adcs-alternatives.png","Looking for ADCS, ADCA, or Microsoft CA alternatives? Active Directory Certificate Services adds complexity modern environments don't need. Here's what to look for in a replacement.","/posts/adcs-alternatives","posts/adcs-alternatives",[501,502,485,503],"ADCS","Alternatives","Active Directory Certificate Services",{"id":505,"title":506,"author":507,"cta":341,"description":508,"hideInRecent":343,"layout":344,"meta":509,"moment":494,"path":513,"stem":514,"tags":515,"webcast":343},"content_en/posts/microsoft-cloud-pki-alternatives.md","Microsoft Cloud PKI Alternatives in 2026",[130],"Microsoft Cloud PKI is designed for issuing certificates to Intune-managed devices. It works well for mobile and endpoint management in Microsoft-centric environments.",{"lang":4,"date":494,"categories":510,"blogtitlepic":511,"customExcerpt":512},[13],"header-scepman-cloud-pki-alternatives.png","Looking for Microsoft Cloud PKI alternatives? Cloud PKI only covers Intune-managed devices — no Linux, no servers, no IoT. Here's where it falls short and what to look for in a replacement.","/posts/microsoft-cloud-pki-alternatives","posts/microsoft-cloud-pki-alternatives",[516,502,517,485],"Microsoft Cloud PKI","Microsoft Intune",{"id":519,"title":520,"author":521,"cta":341,"description":332,"hideInRecent":343,"layout":344,"meta":522,"moment":523,"path":527,"stem":528,"tags":529,"webcast":343},"content_en/posts/microsoft-cloud-pki-iot-certificates.md","Creating IoT Certificates with Microsoft Cloud PKI: Your Alternatives and Solutions",[130],{"lang":4,"date":523,"categories":524,"blogtitlepic":525,"customExcerpt":526},"2026-03-25",[13],"header-scepman-iot-certificates.png","Are you looking for a way to create and manage certificates for IoT devices using Microsoft Cloud PKI? Unfortunately, Microsoft Cloud PKI does not support IoT certificates. By design it only supports Intune managed devices.","/posts/microsoft-cloud-pki-iot-certificates","posts/microsoft-cloud-pki-iot-certificates",[516,530,517],"IoT Certificates",{"id":532,"title":533,"author":534,"cta":341,"description":332,"hideInRecent":343,"layout":344,"meta":535,"moment":523,"path":539,"stem":540,"tags":541,"webcast":343},"content_en/posts/microsoft-cloud-pki-linux-certificates.md","Creating Linux Endpoint Certificates with Microsoft Cloud PKI: Your Alternatives and Solutions",[130],{"lang":4,"date":523,"categories":536,"blogtitlepic":537,"customExcerpt":538},[13],"header-scepman-linux-endpoint-certificates.png","Are you searching for a solution to create and manage certificates for Linux endpoints with Microsoft Cloud PKI? Unfortunately, Microsoft Cloud PKI does not support Linux endpoint certificates.","/posts/microsoft-cloud-pki-linux-certificates","posts/microsoft-cloud-pki-linux-certificates",[516,542,517],"Linux Endpoint Certificates",{"id":544,"title":545,"author":546,"cta":341,"description":332,"hideInRecent":343,"layout":344,"meta":547,"moment":523,"path":551,"stem":552,"tags":553,"webcast":343},"content_en/posts/microsoft-cloud-pki-manually-issuing-certificates.md","Manually Issuing Certificates with Microsoft Cloud PKI: Your Alternatives and Solutions",[130],{"lang":4,"date":523,"categories":548,"blogtitlepic":549,"customExcerpt":550},[13],"header-scepman-manual-certificates.png","Do you need to manually issue certificates for specific scenarios, such as securing web servers, signing code, or other use cases? Unfortunately, Microsoft Cloud PKI does not support manual certificate issuance. By design, it only supports Intune managed devices.","/posts/microsoft-cloud-pki-manually-issuing-certificates","posts/microsoft-cloud-pki-manually-issuing-certificates",[516,554,517],"Manually Issued Certificates",{"id":556,"title":557,"author":558,"cta":341,"description":332,"hideInRecent":343,"layout":344,"meta":559,"moment":523,"path":563,"stem":564,"tags":565,"webcast":343},"content_en/posts/microsoft-cloud-pki-network-device-certificates.md","Creating Certificates for Network Devices with Microsoft Cloud PKI: Your Alternatives and Solutions",[130],{"lang":4,"date":523,"categories":560,"blogtitlepic":561,"customExcerpt":562},[13],"header-scepman-certificates-network-devices.png","Are you searching for a solution to create and manage certificates for network devices with Microsoft Cloud PKI? Unfortunately, Microsoft Cloud PKI does not support network devices certificates. By design it only supports Intune managed devices, only.","/posts/microsoft-cloud-pki-network-device-certificates","posts/microsoft-cloud-pki-network-device-certificates",[516,566,517],"Network Device Certificates",{"id":568,"title":569,"author":570,"cta":341,"description":332,"hideInRecent":343,"layout":344,"meta":571,"moment":523,"path":575,"stem":576,"tags":577,"webcast":343},"content_en/posts/microsoft-cloud-pki-server-certificates.md","Creating Server Certificates with Microsoft Cloud PKI: Alternatives and Solutions",[130],{"lang":4,"date":523,"categories":572,"blogtitlepic":573,"customExcerpt":574},[13],"header-scepman-server-certificates.png","Are you looking for a way to create server certificates using Microsoft Cloud PKI? Many organizations rely on Microsoft's PKI solutions for certificate management, but there’s a significant limitation: Microsoft Cloud PKI does not support server certificates. By design it only supports Intune managed devices, only.","/posts/microsoft-cloud-pki-server-certificates","posts/microsoft-cloud-pki-server-certificates",[516,578,517],"Server Certificates",{},1790694608124]