MicrosoftMicrosoft Intune

    Cloud PKI

    Cloud-based certificate lifecycle management — no on-premises PKI to run.

    Microsoft Cloud PKI is a cloud-based public key infrastructure service that issues and manages certificates for Intune-managed devices — for authentication, Wi-Fi, VPN, and more — without deploying, managing, or securing on-premises PKI infrastructure. Faltrox designs and operates it as managed certificate lifecycle.

    Overview

    What Cloud PKI is

    Certificates underpin secure authentication — for Wi-Fi, VPN, and device and user identity — but running the on-premises public key infrastructure to issue and manage them is complex, costly, and a security responsibility in itself. Microsoft Cloud PKI provides that certificate lifecycle as a cloud service, integrated with Intune.

    It issues and manages certificates for Intune-managed devices — for Wi-Fi, VPN, authentication, and other uses — with a cloud-based certificate authority, automated issuance and renewal, and revocation, without you deploying, managing, patching, or securing on-premises PKI. It removes the operational burden and security risk of self-hosted PKI. Faltrox designs the certificate architecture and operates it as managed certificate lifecycle.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Device & User Certificates

    Issues certificates for device and user authentication.

    02

    Wi-Fi & VPN

    Certificates for secure Wi-Fi and VPN access.

    03

    Automated Lifecycle

    Automated issuance, renewal, and revocation of certificates.

    04

    Cloud CA

    A cloud-based certificate authority with no on-premises PKI.

    05

    No PKI to Run

    No on-premises PKI to deploy, manage, patch, or secure.

    06

    Intune Integration

    Issues certificates to Intune-managed devices automatically.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Set Up

      A cloud-based certificate authority is set up with no on-premises PKI to deploy.

    2. 02

      Issue

      Certificates are issued automatically to Intune-managed devices for Wi-Fi, VPN, and authentication.

    3. 03

      Renew

      Certificates are renewed automatically before expiry to avoid outages.

    4. 04

      Revoke

      Certificates are revoked when a device is retired or compromised.

    5. 05

      Operate

      Faltrox designs the certificate architecture and operates it as managed certificate lifecycle.

    Capabilities

    Key capabilities

    Cloud Certificate Authority

    A cloud-based CA with no on-premises PKI infrastructure to run.

    Automated Issuance

    Issues certificates automatically to Intune-managed devices.

    Automated Renewal

    Renews certificates automatically before expiry to avoid outages.

    Revocation

    Revokes certificates when a device is retired or compromised.

    Wi-Fi & VPN Certificates

    Certificates for secure Wi-Fi and VPN access.

    Authentication Certificates

    Certificates for device and user authentication.

    No PKI Overhead

    Removes the operational burden and security risk of self-hosted PKI.

    Intune Integration

    Integrated with Intune for automated device certificate management.

    Works with

    Part of the platform

    Microsoft products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Microsoft Cloud PKI for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Why use Cloud PKI instead of running our own?

    Running on-premises PKI to issue and manage certificates is complex, costly, and a security responsibility in itself — a compromised CA is catastrophic. Cloud PKI provides certificate lifecycle as a managed cloud service, removing the operational burden and the risk of self-hosted PKI.

    02What are the certificates used for?

    Secure Wi-Fi and VPN access, and device and user authentication — the certificate-based authentication that underpins passwordless and strong access. Cloud PKI issues and manages these for Intune-managed devices automatically.

    03Does it handle renewal and revocation?

    Yes — it automates the full lifecycle: issuance, renewal before expiry (avoiding certificate-expiry outages), and revocation when a device is retired or compromised. That automation is a large part of the value over manual certificate management.

    04Is it part of the Intune Suite?

    Yes — Cloud PKI is included in the Intune Suite and available as a standalone add-on. Faltrox helps choose the licensing that fits your certificate needs.

    05How does Faltrox operate it?

    We design the certificate architecture, configure the cloud CA and issuance to Intune-managed devices, and operate the lifecycle — delivering managed certificate lifecycle without you running on-premises PKI.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us