Managing client certificates

Download a client certificate

  • Certificate only

  • Certificate and private key ( Key Vault )

  • Certificate and private key ( Legacy )

  1. Navigate to Certificates  Client Certificates.

  2. Select the certificate you want to download, and click View.

  3. In the Client Certificate dialog, click the Download icon.

  4. Select the certificate download format.

  1. Navigate to Certificates  Client Certificates.

    You can also recover client certificate private keys from the Persons page.
  2. Select the certificate for which you want to recover the private key, and click View.

  3. In the Client Certificate dialog, click the Download icon, and select Certificate and Private key, PKCS#12, Key Vault.

  4. Enter a password for the downloaded .p12 file.

  5. Select an encryption algorithm.

  6. Click Download.

Retrieving a client certificate private key from secure storage results in the revocation of that certificate, regardless of the administrator’s level.
  1. Navigate to Certificates  Client Certificates.

    You can also recover client certificate private keys from the Persons page.
  2. Select the certificate for which you want to recover the private key, and click View.

  3. In the Client Certificate dialog, click the Download icon, and select Certificate and Private key, PKCS#12, Legacy.

  4. Enter a password for the downloaded .p12 file.

  5. Paste the encryption private key.

  6. Select an encryption algorithm.

  7. Click Download.

Export a client certificate and private key to Intune

Exporting a client certificate and private key requires the configuration of Intune Exporter. For more information, see Configuring Intune Exporter.
  1. Navigate to Certificates  Client Certificates.

  2. Select the certificate for which you want to export the private key, and click Export to Intune.

  3. Click OK.

Delete an client certificate entry

Deleting a client certificate entry does not revoke the certificate itself.
  1. Navigate to Certificates  Client Certificates.

  2. Select the certificate entry you want to delete, and click the Delete icon.

  3. Click Delete.

Revoke a client certificate

  1. Navigate to Certificates  Client Certificates.

  2. Select the certificate you want to revoke, and click Revoke.

  3. In the Revocation Reason dialog, select a revocation reason.

  4. Provide a message outlining any relevant details about the certificate or revocation.

  5. Click Revoke.