Skip to content

Manage policies in Zero Touch PKI

When configuring your instance, add certificate policies to define how Zero Touch PKI issues certificates in your environment. You add policies directly to organizations, using templates defined by CyberArk. Update existing policies by uploading a new YAML configuration file.

About policy deletion

You cannot delete certificate policies once created. Under our data retention policy, any certificate policy used to issue certificates must be kept for seven years past the expiration of its last issued certificate. To remove unused policies or hide deprecated ones, contact CyberArk Support.

Prerequisites

To add a certificate policy

  1. Sign in to Zero Touch PKI.
  2. Click Accounts.
  3. Click your account title.
  4. In Organizations, select an organization.
  5. In Policies, click Create Policy from Template.

    Adding policies from a template

  6. In the dialog, do the following:

  7. Select a Policy Template.
  8. Enter a Policy Name, such as Intune Machine RSA.
  9. Click Create Policy.
    Zero Touch PKI creates the policy for that organization.

To edit a certificate policy

  1. Sign in to Zero Touch PKI.
  2. Click Accounts.
  3. Click your account title.
  4. In Organizations, select an organization.
  5. Go to Polices and find the policy to update.
  6. On the right, in the three-dot menu, select Update Policy.
  7. Click Update Policy and choose a YAML configuration file.
  8. Click Update Policy.
    Zero Touch PKI updates the policy.