Cloud PKI
Cloud-based certificate lifecycle management — no on-premises PKI to run.
Microsoft Cloud PKI is a cloud-based public key infrastructure service that issues and manages certificates for Intune-managed devices — for authentication, Wi-Fi, VPN, and more — without deploying, managing, or securing on-premises PKI infrastructure. Faltrox designs and operates it as managed certificate lifecycle.
Overview
What Cloud PKI is
Certificates underpin secure authentication — for Wi-Fi, VPN, and device and user identity — but running the on-premises public key infrastructure to issue and manage them is complex, costly, and a security responsibility in itself. Microsoft Cloud PKI provides that certificate lifecycle as a cloud service, integrated with Intune.
It issues and manages certificates for Intune-managed devices — for Wi-Fi, VPN, authentication, and other uses — with a cloud-based certificate authority, automated issuance and renewal, and revocation, without you deploying, managing, patching, or securing on-premises PKI. It removes the operational burden and security risk of self-hosted PKI. Faltrox designs the certificate architecture and operates it as managed certificate lifecycle.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Device & User Certificates
Issues certificates for device and user authentication.
Wi-Fi & VPN
Certificates for secure Wi-Fi and VPN access.
Automated Lifecycle
Automated issuance, renewal, and revocation of certificates.
Cloud CA
A cloud-based certificate authority with no on-premises PKI.
No PKI to Run
No on-premises PKI to deploy, manage, patch, or secure.
Intune Integration
Issues certificates to Intune-managed devices automatically.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Set Up
A cloud-based certificate authority is set up with no on-premises PKI to deploy.
- 02
Issue
Certificates are issued automatically to Intune-managed devices for Wi-Fi, VPN, and authentication.
- 03
Renew
Certificates are renewed automatically before expiry to avoid outages.
- 04
Revoke
Certificates are revoked when a device is retired or compromised.
- 05
Operate
Faltrox designs the certificate architecture and operates it as managed certificate lifecycle.
Capabilities
Key capabilities
Cloud Certificate Authority
A cloud-based CA with no on-premises PKI infrastructure to run.
Automated Issuance
Issues certificates automatically to Intune-managed devices.
Automated Renewal
Renews certificates automatically before expiry to avoid outages.
Revocation
Revokes certificates when a device is retired or compromised.
Wi-Fi & VPN Certificates
Certificates for secure Wi-Fi and VPN access.
Authentication Certificates
Certificates for device and user authentication.
No PKI Overhead
Removes the operational burden and security risk of self-hosted PKI.
Intune Integration
Integrated with Intune for automated device certificate management.
Works with
Part of the platform
Microsoft products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Microsoft Cloud PKI for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Why use Cloud PKI instead of running our own?
Running on-premises PKI to issue and manage certificates is complex, costly, and a security responsibility in itself — a compromised CA is catastrophic. Cloud PKI provides certificate lifecycle as a managed cloud service, removing the operational burden and the risk of self-hosted PKI.
02What are the certificates used for?
Secure Wi-Fi and VPN access, and device and user authentication — the certificate-based authentication that underpins passwordless and strong access. Cloud PKI issues and manages these for Intune-managed devices automatically.
03Does it handle renewal and revocation?
Yes — it automates the full lifecycle: issuance, renewal before expiry (avoiding certificate-expiry outages), and revocation when a device is retired or compromised. That automation is a large part of the value over manual certificate management.
04Is it part of the Intune Suite?
Yes — Cloud PKI is included in the Intune Suite and available as a standalone add-on. Faltrox helps choose the licensing that fits your certificate needs.
05How does Faltrox operate it?
We design the certificate architecture, configure the cloud CA and issuance to Intune-managed devices, and operate the lifecycle — delivering managed certificate lifecycle without you running on-premises PKI.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us