Skip to content
CBA Field Guide
Interactive implementation guide

Certificate sign-in,
without the guesswork.

Build a Radius365 issuing path, deliver user certificates with Intune, and enable Microsoft Entra CBA through a controlled pilot.

Guided pilot45–60 min
Systems4 connected
Rollout modelPilot first
Certificate moving through a cloud trust path
FIELD01CBA / 2026
Built for a controlled pilot
01 / TRUST MODEL

Certificate journey

Select a node to see its responsibility.

PLATE / A
Radius365

Issues, renews and revokes the certificate; publishes the CRL.

02 / PRE-FLIGHT

Before you touch the tenant

A good CBA rollout starts with a safe test boundary, not an authentication toggle.

Never target All users in the first pass.
Pilot readiness0/4
4 checks remaining
00 / 08
00Entra5 min
Start safely

Plan a small, reversible pilot.

STEP00
Outcome

A pilot group, one test device and a break-glass account that will not be affected.

Required roleAuthentication Policy Administrator

Before you begin

Choose 2–5 pilot users on managed devices.

Keep at least one emergency account outside every CBA policy.

Do this

  1. 01

    Create an Entra security group named CBA-Pilot.

  2. 02

    Add only test users and record the owner of the rollout.

  3. 03

    Confirm that a fallback authentication method works before continuing.

CHECKPOINT

Verify before continuing

03 / DIAGNOSE

Troubleshoot by symptom

Start with the system that reported the failure. CBA is a chain; the error is usually local to one link.

Intune

SCEP profile stays Pending

Verify the Trusted certificate profile reached the device first and that the SCEP profile references it.

Radius365

Intune rejected SCEP request

Re-check Intune admin consent, user-group assignment and the allowed subject/SAN values.

Device

Certificate exists but has no private key

Re-enroll through the SCEP profile; do not import only the public .cer as a user certificate.

Entra

Certificate option does not appear

Check pilot targeting, CBA enablement, certificate availability and the complete trust chain.

Entra

AADSTS certificate mapping error

Inspect the certificate SAN and compare the configured username binding with the actual Entra user attribute.

Revocation

Revoked certificate still signs in

Use a new private session, confirm the CRL was republished, and verify that Entra points to the public HTTP CRL URL.

FIELD NOTE / 09

A certificate sign-in is only as strong as its rollout.

You now have a safer implementation path: issue, deploy, trust, bind, pilot, revoke — then scale with evidence.

IMPLEMENTATION PATH
0%guide completed

Interfaces change. Confirm labels against current Microsoft documentation before production rollout.