Setting up and managing device configurations using Intune
For PKCS on Intune, changing or updating the PKCS profile does not remove or revoke the existing certificate on the device. On Windows, iOS, macOS, and Android KNOX, PKCS certificates stay on the device when an administrator changes or updates the PKCS profile.
If a PKCS certificate is manually deleted from the device while the device is still targeted by the certificate policy, Intune detects that the expected certificate is missing at the next device check-in and issues a new certificate automatically.
Supported behavior from the documentation:
- Editing the PKCS profile alone: the existing PKCS certificate stays on the device.
- To force a new certificate issuance: remove the existing certificate from the device. At the next Intune check-in, Intune issues a new certificate if the device or user is still targeted by the profile.
- Profile targeting changes:
- On Windows, a PKCS certificate is removed when the PKCS certificate profile no longer targets the device or user.
- On iOS, a PKCS certificate is removed when the certificate profile is removed from the group assignment.
- On macOS and Android KNOX, PKCS certificates can stay on the device even if the profile is removed from the group assignment.
The provided documentation does not state that the certificate must be removed from the Certification Authority before Intune repushes a new PKCS certificate.