nerdexam
Microsoft

MD-102 · Question #536

You have a Microsoft 365 subscription and use Microsoft Intune Suite. You plan to use Microsoft Cloud PKI to support the signing and encryption of email messages. What should you do first?

The correct answer is A. Create a root certification authority (CA).. To utilize Microsoft Cloud PKI for email signing and encryption, the first step is to establish the trust anchor by creating a root certification authority (CA).

Submitted by haruto_sh· Apr 18, 2026Prepare infrastructure for devices

Question

You have a Microsoft 365 subscription and use Microsoft Intune Suite. You plan to use Microsoft Cloud PKI to support the signing and encryption of email messages. What should you do first?

Options

  • ACreate a root certification authority (CA).
  • BCreate a device compliance policy.
  • CCreate device configuration SCEP certificate profiles.
  • DCreate device configuration trusted certificate profiles.
  • ECreate an issuing certification authority (CA).

How the community answered

(32 responses)
  • A
    81% (26)
  • B
    3% (1)
  • C
    9% (3)
  • D
    3% (1)
  • E
    3% (1)

Why each option

To utilize Microsoft Cloud PKI for email signing and encryption, the first step is to establish the trust anchor by creating a root certification authority (CA).

ACreate a root certification authority (CA).Correct

In a Public Key Infrastructure (PKI), a root certification authority (CA) is the absolute trust anchor and the foundational component that signs all other certificates in the hierarchy, including issuing CAs. Before any subordinate or issuing CAs can be created or certificates issued for email signing and encryption, the root CA must be established to provide the initial trust for the entire PKI solution.

BCreate a device compliance policy.

Device compliance policies are used to enforce security standards on devices, but they are not the initial step in setting up a PKI infrastructure.

CCreate device configuration SCEP certificate profiles.

SCEP certificate profiles are used to deploy certificates to devices *after* the CA hierarchy is established and certificates can be issued.

DCreate device configuration trusted certificate profiles.

Trusted certificate profiles are used to push trusted root or intermediate certificates to devices, which is done *after* the CAs are created.

ECreate an issuing certification authority (CA).

An issuing certification authority (CA) is a subordinate CA that issues end-entity certificates, but it cannot be created before its parent root CA is established.

Concept tested: Microsoft Cloud PKI foundational components: Root CA creation

Source: https://learn.microsoft.com/en-us/mem/intune/protect/microsoft-cloud-pki-overview

Topics

#Cloud PKI#Root CA#Email Signing#Intune

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice