← Microsoft Corporation cases
Bugzilla #1848279 Technical Compliance

Microsoft PKI Services: Trusted Role Control Failure

RESOLVED FIXED Microsoft Corporation
AI Summary

A Microsoft PKI Services engineer discovered that a user account was provisioned for an employee not assigned to a Trusted Role, violating security requirements. This issue was identified during an internal audit on August 9, 2023, leading to the immediate deletion of the account. Although this was a significant process failure, Microsoft PKI Services maintained that the overall environment remained secure. The team has since implemented improvements to the management and verification processes for Trusted Role memberships to prevent recurrence.

Model: gpt-4o-mini Generated: 2026-06-13 21:17 UTC Confidence: 0.90
Chronology
  1. Non-Trusted Role user requested account in High Security Zone
  2. Audit discovered Non-Trusted Role user account; incident opened
  3. User account deleted
  4. Centralized management of Trusted Role group list implemented
  5. Automation for user verification in Secure Zone completed
Participants
u654666@disabled.tld johnmas@microsoft.com bwilson@mozilla.com
External References
Similar Local Cases
#1848280 RESOLVED Technical Compliance Opened 2023-08-11 · Closed 2023-10-12 · 84% similar
Microsoft PKI Services: 3-Month Access Review Process Failure
#1732745 RESOLVED Technical Compliance Opened 2021-09-27 · Closed 2023-02-22 · 48% similar
Certainly: Root CRL validity period exceeds maximum by one second
#1738191 RESOLVED Technical Compliance Opened 2021-10-28 · Closed 2023-02-22 · 47% similar
GDCA: CRL validity period exceeds allowed value by one second
#1711597 RESOLVED Technical Compliance Opened 2021-05-17 · Closed 2023-05-03 · 47% similar
Update Microsoft field names and automate filling in the EV checkboxes based on the Microsoft Policy OIDs
#1914893 RESOLVED Technical Compliance Opened 2024-08-26 · Closed 2024-09-18 · 47% similar
Amazon Trust Services: CRL not DER-encoded
#1793441 RESOLVED Technical Compliance Opened 2022-10-03 · Closed 2023-02-22 · 45% similar
GlobalSign: CRL contains invalid signature algorithm
#1772644 RESOLVED Technical Compliance Opened 2022-06-04 · Closed 2023-02-22 · 44% similar
Apple: CRL issuance frequency deviates from CPS in some cases
#1684112 RESOLVED Technical Compliance Opened 2020-12-23 · Closed 2023-02-22 · 41% similar
Let's Encrypt: Failure to audit log subscriber certificate OCSP updates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action