← Microsoft Corporation cases
Bugzilla #1848279 Self Reported Incident

Microsoft PKI Services: Trusted Role Control Failure

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsoft PKI Services disclosed a process failure involving Trusted Role access controls. The issue was identified by an internal self-audit, which found that a user account had been provisioned for an employee who was not assigned to a Trusted Role but was granted access to a Secure Zone/High Security Zone. The failure did not meet section 2.c. of the Network Security Requirements requiring that only personnel assigned to Trusted Roles have access to Secure Zones and High Security Zones. Microsoft stated that certificates were not impacted by this process failure and that it identified a single problem user account that was deleted quickly after being discovered. Microsoft reported that it updated its manual provisioning process to include an independent check for Trusted Role group membership, and later centralized management of the Trusted Role group list to enable automation. Microsoft requested closure after completing the centralized management work and automation to verify Secure Zone access users against the Trusted Role list. The bug was marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:17 UTC Revised: 2026-06-16 19:22 UTC Confidence: 0.86 6 comments
Chronology
  1. A non-Trusted Role user requested and had an account approved for access to a Secure Zone/High Security Zone outside the normal process.
  2. The user account was created for the non-Trusted Role user outside of process for the Secure Zone/High Security Zone.
  3. A Trusted Role Engineer’s random audit discovered the non-Trusted Role user account in the Secure Zone/High Security Zone and Microsoft opened an internal incident and deleted the account.
  4. Microsoft updated the manual provisioning process to add an independent check for Trusted Role group membership.
  5. Microsoft planned to implement centralized management and improved visibility/automation for the Trusted Role group list.
  6. Microsoft completed centralized management of the Trusted Role group list and added automation to verify Secure Zone users are in an appropriate Trusted Role.
Thread Activity
  1. Disabled representative — Submitted a preliminary report describing the Trusted Role control failure, stating it was discovered via internal self-audit and that the non-Trusted Role user account was deleted after discovery.
  2. Microsoft Corporation — Posted an incident report with the same Trusted Role access-control failure details and referenced a separate bug for a related 3-month access review issue (1848280).
  3. Disabled representative — Provided an update that Trusted Role list management/process improvements were progressing but commitment dates needed adjustment due to staffing.
  4. Disabled representative — Reported finalized commitment dates and described planned centralization and automation for Trusted Role group list verification.
  5. Disabled representative — Stated that centralized management of the Trusted Role group list was completed and automation was added to verify Secure Zone users against the Trusted Role list, requesting closure.
  6. Mozilla representative — Indicated intent to close the bug on 11-Oct-2023.
Participants
Disabled representative Microsoft Corporation Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1848280 RESOLVED Self Reported Incident Opened 2023-08-11 · Closed 2023-10-12 · 100% similar
Microsoft PKI Services: 3-Month Access Review Process Failure
#1906028 RESOLVED Self Reported Incident Audit Finding Opened 2024-07-03 · Closed 2024-08-15 · 98% similar
Microsoft PKI Services: Vulnerability Management Exception Tracking
#1705419 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-15 · Closed 2023-02-22 · 95% similar
Microsoft PKI Services: Underscore in SAN
#1711147 RESOLVED Self Reported Incident Opened 2021-05-13 · Closed 2023-02-22 · 95% similar
Microsoft PKI Services: Malformed ICAs (missing certificate policy extensions)
#1793443 RESOLVED Self Reported Incident Opened 2022-10-03 · Closed 2024-05-09 · 95% similar
Microsoft PKI Services: "unknown" OCSP response for issued certificates
#1740585 RESOLVED Self Reported Incident Opened 2021-11-10 · Closed 2024-05-09 · 86% similar
Microsoft PKI Services: Unrevoked 4 intermediate certificates
#1979475 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-07-26 · Closed 2026-01-20 · 82% similar
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints)
#2026452 RESOLVED Self Reported Incident Audit Delay Opened 2026-03-26 · Closed 2026-04-22 · 80% similar
Microsoft PKI Services: Failure to publish Full Incident Report for Bugzilla 2021175 within 14 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action