← Microsoft Corporation cases
Bugzilla #1848280 Self Reported Incident

Microsoft PKI Services: 3-Month Access Review Process Failure

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsoft PKI Services reported a self-identified process failure in its 3-month access review process. During investigation of another issue, it became clear on 2023-08-10 that the 3-Month Access Review Process failed to identify a user account that had been provisioned for an employee not assigned to a Trusted Role, contrary to Network Security Requirements Section 2.j. Microsoft stated that certificates were not impacted by this process failure and that certificate issuance was not stopped. Microsoft described actions taken in response, including deleting the non-Trusted Role user account on 2023-08-09 and updating the manual 3-month access review process on 2023-08-17 to include an explicit check for Trusted Role group membership. Microsoft later reported automation work to collect and verify user accounts for 3-month access reviews and to automate verification that Secure Zone users are in the Trusted Role group, with implementation reported as completed by 2023-10-13. Microsoft then requested closure after completing centralized management of the Trusted Role group list to replace manual processes. Mozilla indicated it intended to close the bug on 11-Oct-2023, and the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:18 UTC Revised: 2026-06-16 19:22 UTC Confidence: 0.86 6 comments
Chronology
  1. A user account was created for a Non-Trusted Role user.
  2. A Trusted Role Engineer performed a random audit and discovered a Non-Trusted Role user account in the High Security Zone, then opened an internal incident and deleted the account.
  3. Microsoft determined that the 3-Month Access Review Process failed to identify the access issue.
  4. Microsoft updated the manual 3-month access review process to explicitly check Trusted Role group membership.
  5. Microsoft completed centralized management of the Trusted Role group list and added automation to verify Secure Zone users are in the Trusted Role group.
Thread Activity
  1. Disabled representative — Submitted a preliminary report describing a self-identified failure of the 3-month access review process to identify a non-Trusted Role user account and citing Network Security Requirements Section 2.j.
  2. Microsoft Corporation — Posted an incident report with the same self-identified issue, including a timeline and the statement that certificates were not impacted.
  3. Disabled representative — Reported updates to the manual 3-month review process (at least every 90 days) and progress on automation for collecting user accounts for 3-month access reviews.
  4. Disabled representative — Reported verification of automation data collection on 2023-08-29 and stated automation to verify Secure Zone users against the Trusted Role group would be implemented by 2023-10-13.
  5. Disabled representative — Reported completion of centralized management of the Trusted Role group list and requested closure of the bug.
  6. Mozilla representative — Stated intent to close the bug on Wed 11-Oct-2023.
Participants
Disabled representative Microsoft Corporation Mozilla representative
External References
Similar Local Cases
#1848279 RESOLVED Self Reported Incident Opened 2023-08-11 · Closed 2023-10-12 · 100% similar
Microsoft PKI Services: Trusted Role Control Failure
#1711147 RESOLVED Self Reported Incident Opened 2021-05-13 · Closed 2023-02-22 · 97% similar
Microsoft PKI Services: Malformed ICAs (missing certificate policy extensions)
#1906028 RESOLVED Self Reported Incident Audit Finding Opened 2024-07-03 · Closed 2024-08-15 · 97% similar
Microsoft PKI Services: Vulnerability Management Exception Tracking
#1705419 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-15 · Closed 2023-02-22 · 95% similar
Microsoft PKI Services: Underscore in SAN
#1793443 RESOLVED Self Reported Incident Opened 2022-10-03 · Closed 2024-05-09 · 95% similar
Microsoft PKI Services: "unknown" OCSP response for issued certificates
#1740585 RESOLVED Self Reported Incident Opened 2021-11-10 · Closed 2024-05-09 · 88% similar
Microsoft PKI Services: Unrevoked 4 intermediate certificates
#1999850 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2025-11-13 · Closed 2026-07-01 · 80% similar
Microsoft PKI Services: OCSP Non-Compliance
#1979475 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-07-26 · Closed 2026-01-20 · 80% similar
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action