Can I use our existing certificate authority instead of yours?
Not today. Passbeam provisions and runs a certificate authority per client, and there is no import path for an external one — a certificate has to chain to the authority Passbeam issued for that client, or it is refused.
For most people that is the point rather than a restriction: not running a CA is half of what this replaces, and the per-client authority is what stops one customer's certificates meaning anything on another customer's network.
It is a fair question if you already have a PKI you trust and a reason to keep it, and it is on the list to look at properly rather than dismissed. If that is you, say so — it changes the priority, and knowing what you need it to do is worth more to us than a guess. The half that would take work is issuance; trusting an external root is the smaller part.
Related questions
- Why does every device need the Trusted Root CA installed?
- What is SCEP, and how does it work?
- Can I use Jamf, Mosyle, Kandji or another MDM instead of Intune?
- Device certificates or user certificates — what is the difference?
- Can I change a client's certificate mode after setup?
- Can I use Passbeam for a network with no Entra ID at all — printers, cameras, door access, building controls?
- How do I set up printers, CCTV, BMS and IoT devices that support 802.1X?
- What happens when a certificate is about to expire?
Still stuck? Ask us, or read the rest of the knowledge base.