Post-Quantum Authentication: Start PKI Testing Now
Summary
Microsoft is urging organizations to begin testing certificate ecosystems now for post-quantum authentication readiness. The company’s PQC TLS Pilot Program and Windows 11 support for ML-DSA certificates give PKI teams a controlled way to identify interoperability, performance, and operational issues before production adoption becomes necessary.
Introduction
Post-quantum cryptography planning often centers on protecting encrypted data, but Microsoft says authentication may be the harder operational challenge. For IT and security teams, the shift affects not just algorithms, but the full certificate ecosystem: PKI services, trust anchors, applications, devices, and hardware security modules.
What’s new
Microsoft is encouraging organizations to begin post-quantum authentication testing now rather than waiting for future mandates or broad production support.
Key developments include:
- PQC TLS Pilot Program: Microsoft launched a controlled pilot for eligible certificate authorities in the Microsoft Trusted Root Program.
- ML-DSA-87 testing: The pilot uses the quantum-resistant Module-Lattice-Based Digital Signature Algorithm (ML-DSA-87) for TLS certificate testing.
- Non-production only: Pilot certificates are not publicly trusted and must only be used in closed environments, custom apps, and enterprise test labs.
- Windows 11 support: Supported and properly configured Windows 11 systems can evaluate ML-DSA certificates in pilot scenarios, including supported Schannel use cases.
Why this matters
Microsoft’s main message is that post-quantum authentication is not a simple certificate replacement project. Many organizations lack a complete inventory of systems that issue, validate, store, or depend on certificates.
That creates several risks:
- Larger certificate chains may affect handshake size, storage, and performance.
- Legacy apps and embedded systems may fail to process new certificate formats.
- PKI workflows and certificate lifecycle processes may need redesign.
- HSMs, network inspection tools, and third-party services may not yet be ready.
For administrators, the challenge is less about whether a single certificate can work and more about whether the entire ecosystem can operate reliably at scale.
Impact on IT administrators
PKI admins, architects, and security leaders should treat this as a multi-year readiness effort. Early testing can reveal hidden dependencies across internal PKI, operational technology, appliances, and vendor-managed services.
Microsoft also notes that platform support is still evolving, so organizations should not treat current pilot capabilities as production-ready. Instead, this is an opportunity to identify compatibility gaps before post-quantum authentication becomes a business requirement.
Next steps
Organizations should start with practical preparation steps now:
- Inventory certificate-dependent systems and workflows.
- Identify long-lived infrastructure and devices with fixed cryptographic assumptions.
- Review vendor roadmaps for PQC and certificate support.
- Build non-production test environments for interoperability testing.
- Validate Windows 11 and Schannel requirements before pilot testing.
The takeaway is clear: post-quantum authentication readiness starts with visibility and testing. Teams that begin now will be in a stronger position as standards, tooling, and platform support mature.
Need help with Security?
Our experts can help you implement and optimize your Microsoft solutions.
Talk to an ExpertStay updated on Microsoft technologies