← Microsoft Corporation cases
Bugzilla #1848280 Technical Compliance

Microsoft PKI Services: 3-Month Access Review Process Failure

RESOLVED FIXED Microsoft Corporation
AI Summary

Microsoft PKI Services identified a failure in their 3-Month Access Review Process, which did not detect a user account provisioned for an employee not in a Trusted Role. This oversight was discovered during an internal audit on August 9, 2023, and highlighted a need for improved compliance with security requirements. Although the issue was serious, Microsoft confirmed that certificate issuance continued and that the environment remained secure. Steps have been taken to enhance the review process and automate user verification to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:18 UTC Confidence: 0.95
Chronology
  1. User account created for Non-Trusted Role user
  2. Random audit discovered Non-Trusted Role user account
  3. Investigation identified 3-Month Access Review process problem
  4. Centralized management of Trusted Role group list completed
Participants
u654666@disabled.tld johnmas@microsoft.com bwilson@mozilla.com
External References
Similar Local Cases
#1848279 RESOLVED Technical Compliance Opened 2023-08-11 · Closed 2023-10-12 · 84% similar
Microsoft PKI Services: Trusted Role Control Failure
#1738191 RESOLVED Technical Compliance Opened 2021-10-28 · Closed 2023-02-22 · 50% similar
GDCA: CRL validity period exceeds allowed value by one second
#1732745 RESOLVED Technical Compliance Opened 2021-09-27 · Closed 2023-02-22 · 49% similar
Certainly: Root CRL validity period exceeds maximum by one second
#1711597 RESOLVED Technical Compliance Opened 2021-05-17 · Closed 2023-05-03 · 48% similar
Update Microsoft field names and automate filling in the EV checkboxes based on the Microsoft Policy OIDs
#1914893 RESOLVED Technical Compliance Opened 2024-08-26 · Closed 2024-09-18 · 48% similar
Amazon Trust Services: CRL not DER-encoded
#1772644 RESOLVED Technical Compliance Opened 2022-06-04 · Closed 2023-02-22 · 47% similar
Apple: CRL issuance frequency deviates from CPS in some cases
#1793441 RESOLVED Technical Compliance Opened 2022-10-03 · Closed 2023-02-22 · 46% similar
GlobalSign: CRL contains invalid signature algorithm
#1684112 RESOLVED Technical Compliance Opened 2020-12-23 · Closed 2023-02-22 · 43% similar
Let's Encrypt: Failure to audit log subscriber certificate OCSP updates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action