Security

Post-Quantum Authentication: Start PKI Testing Now

3 min read

Summary

Microsoft is urging organizations to begin testing certificate ecosystems now for post-quantum authentication readiness. The company’s PQC TLS Pilot Program and Windows 11 support for ML-DSA certificates give PKI teams a controlled way to identify interoperability, performance, and operational issues before production adoption becomes necessary.

Need help with Security?Talk to an Expert

Introduction

Post-quantum cryptography planning often centers on protecting encrypted data, but Microsoft says authentication may be the harder operational challenge. For IT and security teams, the shift affects not just algorithms, but the full certificate ecosystem: PKI services, trust anchors, applications, devices, and hardware security modules.

What’s new

Microsoft is encouraging organizations to begin post-quantum authentication testing now rather than waiting for future mandates or broad production support.

Key developments include:

  • PQC TLS Pilot Program: Microsoft launched a controlled pilot for eligible certificate authorities in the Microsoft Trusted Root Program.
  • ML-DSA-87 testing: The pilot uses the quantum-resistant Module-Lattice-Based Digital Signature Algorithm (ML-DSA-87) for TLS certificate testing.
  • Non-production only: Pilot certificates are not publicly trusted and must only be used in closed environments, custom apps, and enterprise test labs.
  • Windows 11 support: Supported and properly configured Windows 11 systems can evaluate ML-DSA certificates in pilot scenarios, including supported Schannel use cases.

Why this matters

Microsoft’s main message is that post-quantum authentication is not a simple certificate replacement project. Many organizations lack a complete inventory of systems that issue, validate, store, or depend on certificates.

That creates several risks:

  • Larger certificate chains may affect handshake size, storage, and performance.
  • Legacy apps and embedded systems may fail to process new certificate formats.
  • PKI workflows and certificate lifecycle processes may need redesign.
  • HSMs, network inspection tools, and third-party services may not yet be ready.

For administrators, the challenge is less about whether a single certificate can work and more about whether the entire ecosystem can operate reliably at scale.

Impact on IT administrators

PKI admins, architects, and security leaders should treat this as a multi-year readiness effort. Early testing can reveal hidden dependencies across internal PKI, operational technology, appliances, and vendor-managed services.

Microsoft also notes that platform support is still evolving, so organizations should not treat current pilot capabilities as production-ready. Instead, this is an opportunity to identify compatibility gaps before post-quantum authentication becomes a business requirement.

Next steps

Organizations should start with practical preparation steps now:

  • Inventory certificate-dependent systems and workflows.
  • Identify long-lived infrastructure and devices with fixed cryptographic assumptions.
  • Review vendor roadmaps for PQC and certificate support.
  • Build non-production test environments for interoperability testing.
  • Validate Windows 11 and Schannel requirements before pilot testing.

The takeaway is clear: post-quantum authentication readiness starts with visibility and testing. Teams that begin now will be in a stronger position as standards, tooling, and platform support mature.

Need help with Security?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

post-quantum cryptographyPKIcertificatesTLSMicrosoft Security

Related Posts

Security

Frontier AI Vulnerability Research: 3 Security Lessons

Microsoft Security’s FORGE Lab shared three operational lessons from using AI for vulnerability research at scale across Windows and open-source software. The findings show that the real challenge is no longer just discovering bugs with AI, but validating, deduplicating, and remediating them fast enough to turn research into shipped security fixes.

Security

AI Vulnerability Risks: Microsoft CISO Guidance

Microsoft says AI is dramatically increasing the volume and pace of vulnerability discovery, especially for on-premises software, forcing CISOs to rethink patching and resilience strategies. The company recommends faster patch prioritization, broader use of AI-assisted scanning, and stronger defense-in-depth with Microsoft Baseline Security Mode to reduce exposure.

Security

Microsoft Digital Defense Report 2026: Key Security Insights

Microsoft's 2026 Digital Defense Report highlights how AI and growing system interconnectedness are reshaping both cyberattacks and defense strategies. The report emphasizes that organizations must secure AI, identities, data, and cloud environments together while improving signal correlation across tools to detect modern threats faster.

Security

Government Cyber Risk in 2026: Microsoft’s 5 Priorities

Microsoft says government agencies were the most targeted sector in 2026, accounting for 27% of observed cyber threat activity. The company urges public-sector leaders to focus on five resilience priorities, including faster response, AI security, bidirectional information sharing, and planning for incidents that spread across suppliers and essential services.

Security

Microsoft Ignite 2026 Security Guide: Key Sessions

Microsoft has published its security guide for Microsoft Ignite 2026, highlighting AI-first security themes, a dedicated Security Pre-Day, and technical sessions focused on securing identities, data, devices, clouds, and AI agents. For IT and security teams, the event offers an early look at Microsoft’s roadmap and practical guidance for building an AI-ready security strategy.

Security

CVE-2026-73570: Zimbra Mail Server Exploitation

Microsoft is tracking active exploitation of CVE-2026-73570, an unauthenticated command injection flaw affecting internet-facing Zimbra mail servers with the optional zimbra-snmp package installed and SNMP notifications enabled. The issue can lead to web shell deployment, privilege escalation, mailbox data theft, and persistent remote access, making immediate patching and configuration review critical for administrators.