msnugget
8 By Jannik Reinhard & Florian Salzmann ยท Published ยท Updated

In Place Renewal for Cloud PKI Issuing CAs

So far we needed to create a brand new issuing CA in Cloud PKI every time one was about to expire. Now, finally, we are able to just renew it in place. That alone removes a recurring operational task that never added any real value.

What it enables

In place renewal keeps the CA identity intact while issuing a new certificate underneath it. SCEP profiles, device assignments, and trust chains stay untouched. No reassignment, no resync wave across thousands of devices.

This removes one of the biggest operational risks in Cloud PKI: a CA expiry that silently breaks Wi-Fi, VPN, or email auth because someone missed updating a profile reference after a manual CA swap. Renewal becomes a maintenance task instead of a migration project.

There is one detail worth knowing though. Even an already expired CA can still be renewed, but certificate issuance stays unavailable until the staged CA is actually activated. So expiry is not the end of the world, but it does introduce a gap where new certificates cannot be issued until you complete the activation step.

When to use it

Use in place renewal for any production issuing CA nearing expiry where SCEP profiles are already deployed and working. This is the default path for Wi-Fi, VPN, and email certificate scenarios across managed device fleets, including shared devices and large BYOD populations.

Example scenario

A typical case: an issuing CA created two years ago is approaching expiry. Dozens of SCEP profiles reference it. Previously this meant a planned cutover weekend. With in place renewal, the CA renews, certificate issuance continues, and nobody outside the PKI team needs to know it happened. If you miss the expiry date, renewal still works, but plan for a short gap until the staged CA is activated. (In my case the staging and activation took about 2h)

Recommendation

Default to in place renewal for eligible issuing CAs, ideally before expiry to avoid any issuance gap. If a CA already expired, renew it and activate the staged CA as quickly as possible to restore issuance. Reserve manual CA recreation for actual hierarchy changes, not routine expiry.

References

๐Ÿ”— Renew a certification authority in Cloud PKI

In place renewal turns CA expiry from a migration risk into a non event.

Jannik Reinhard

Head of AI

Jannik brings deep expertise in AI integration, modern infrastructure, and enterprise transformation at scale.

Florian Salzmann

Leading Expert

Florian specializes in Intune, endpoint management, and security with extensive real-world enterprise experience.