Starting July 1, 2026, Microsoft 365 E5 customers get Intune Cloud PKI included at no additional cost. The Intune Suite add-on that used to run $10 USD per user per month is now part of the E5 bundle. If you're on E5, congratulations. You just picked up a managed certificate authority for free.

Which sounds like the end of the ADCS conversation.

It isn't. Because almost no enterprise is 100% E5.

The mixed estate problem

Look at any real enterprise's Microsoft 365 licensing. Executives and IT are usually on E5 for the security features. Standard knowledge workers are on E3 for productivity. Frontline workers (retail, warehouse, manufacturing floor) are on F1 or F3. Contractors and service accounts might be on nothing at all, or on lightweight SKUs that don't include Intune.

The typical mid-market enterprise breaks down something like:

  • 15-30% on E5 (executives, IT, security teams, maybe sales leadership)
  • 50-70% on E3 (the bulk of information workers)
  • 10-20% on F1/F3 (frontline)
  • Some fraction on nothing

Which means when leadership says "we're moving to Cloud PKI because it's free with E5," what they actually mean is "Cloud PKI is free for the 20% of users who are on E5. The other 80% still need to be figured out."

Options for the non-E5 users:

A. Buy them Cloud PKI standalone. Currently $2 USD per user per month as an add-on. Predictable, scales linearly, still costs real money.

B. Upgrade them to E5. The E3-to-E5 delta is about $22 USD per user per month, or roughly $264 per year per upgraded user. That's 11 times the standalone Cloud PKI add-on. Rarely justified by PKI alone.

C. Don't give them certificates. Cuts scope, breaks the deployment for those users. Only viable if certificates aren't required for their work.

D. Keep ADCS running for the non-E5 users. Parallel infrastructure. Requires maintaining both.

E. Hybrid. E5 users get Cloud PKI for their Intune-managed devices. Everyone else gets ADCS. Also requires maintaining both.

Options D and E are what most enterprises actually end up doing. Which means "moving to Cloud PKI" rarely retires ADCS. It layers Cloud PKI on top of ADCS. Both infrastructures continue to exist. Both continue to cost money.

That's the picture most Cloud PKI cost analyses skip past.

The apparent math

Let's pretend for a moment that the picture is simple. All-in on Cloud PKI, retire ADCS entirely. What's the comparison?

A fully redundant on-prem PKI stack that matches what Cloud PKI offers requires seven Windows Server 2025 Standard licenses:

  1. One offline root CA
  2. Two issuing CAs (HA pair)
  3. Two dedicated CDP hosts (redundant HTTP for CRL and AIA)
  4. Two NDES servers (redundant SCEP)

Seven times the Windows Server 2025 Standard 16-core pack at Microsoft's approximate MSRP of $1,176 USD comes to about $8,200 USD. One-time, perpetual. No Datacenter edition needed. Each ADCS role is a single-workload server. Standard covers it.

Cloud PKI at $2 USD per user per month reaches $8,200 per year at 340 users.

So by that math, ADCS pays for itself in less than a year at any enterprise scale, and gets cheaper every year after. Cloud PKI never wins.

Which is completely wrong. Because the Windows Server licenses are the smallest number in the ADCS budget.

The real ADCS TCO

Take a mid-market enterprise: 2,500 users, 4,000 devices (about 1.6 devices per user, accounting for BYOD and shared devices), 5-year horizon.

Windows Server licenses (7 × $1,176): $8,232
Software Assurance for updates and support (25% per year for 5 years): $10,290
Device CALs at approximately $40 per device: $160,000
HSM (entry-level Entrust or Thales including 5 years of support): $25,000
Server hardware or VM allocation for 7 servers: $15,000
PKI engineer time (design, deployment, maintenance, incidents, migrations over 5 years): $100,000
External consulting for hardening, audits, and specialized incident response: $25,000

Total 5-year ADCS TCO for this enterprise: approximately $343,500 USD

Now the same enterprise on Cloud PKI. Assume the typical mixed-estate breakdown:

  • 500 users on E5: Cloud PKI free with license as of July 1, 2026
  • 1,750 users on E3: Cloud PKI standalone add-on at $2 per user per month
  • 250 users on F1/F3: Cloud PKI standalone add-on at $2 per user per month

Non-E5 user count: 2,000
Cloud PKI cost over 5 years: 2,000 users × $2 × 12 × 5 = $240,000 USD

For this specific enterprise, Cloud PKI is cheaper than ADCS by about $100,000 over five years. But only if you can retire ADCS entirely, which almost no enterprise can.

What Cloud PKI doesn't cover

Retiring ADCS is where the cost analysis meets reality. Cloud PKI is only useful for a specific set of scenarios:

  • Certificates for Intune-enrolled Windows, macOS, iOS, and Android devices
  • SCEP-based enrollment through Intune's certificate profiles
  • Wi-Fi, VPN, and 802.1X authentication
  • Some browser-based client authentication

Things Cloud PKI does not do, or does not do well:

  • Linux servers, network switches, routers, load balancers, printers, IoT devices, industrial equipment. If it isn't Intune-managed, it isn't getting a Cloud PKI cert.
  • Email signing and encryption certificates (S/MIME)
  • Code signing certificates
  • Custom EKUs beyond what Intune's profile UI exposes
  • Private key archival for encryption use cases
  • HSM-backed root and issuing CA keys under your control
  • Compliance frameworks that require a physically-controlled certificate authority
  • Cross-certification with external partners
  • Air-gapped or disconnected-network enrollment scenarios

If any of these matter in your environment, and for most enterprises at least three or four of them do, then Cloud PKI cannot fully replace ADCS. Which puts you back into the hybrid model. Which means paying for both.

For our 2,500-user example enterprise, add Cloud PKI for the non-E5 users ($240,000 over 5 years) on top of the existing ADCS TCO ($343,500 over 5 years, or somewhat reduced if the Intune-managed devices no longer need CAL coverage on ADCS). Total combined 5-year cost lands somewhere between $500,000 and $580,000.

Cloud PKI didn't replace ADCS. It became an additional expense.

The break-even math for all-in scenarios

For organizations that genuinely can move entirely to Cloud PKI (no Linux servers, no network gear needing certs, no S/MIME, no code signing, no compliance requirement for on-prem CA), the break-even math is more straightforward:

Fixed ADCS costs that don't scale with user count: approximately $150,000 (licenses, SA, HSM, hardware, baseline engineer time, consulting)

Per-user ADCS costs that scale linearly: about $80 per user over 5 years (CALs on ~1.6 devices per user, small scaling factor on engineer time)

Cloud PKI cost per E3 user over 5 years at standalone pricing: $120

Break-even where Cloud PKI E3 cost equals ADCS variable cost per user: 150,000 + 80u = 120u, solving to u ≈ 3,750 users.

So for an organization on E3 across the board with no E5 to leverage, ADCS becomes cheaper than Cloud PKI standalone at about 3,750 users.

For an all-E5 organization post-July 2026, Cloud PKI is included with the license. ADCS never wins on cost. Cost stops being the deciding factor. The question becomes purely about function.

The decision framework

Simplified for 2026 realities:

If you're 100% E5 and everything you need certificates for is Intune-managed: Cloud PKI wins. Move to it. Retire ADCS. The cost picture is unambiguous, the operational overhead is minimal, and Microsoft absorbs the complexity.

If you're mixed E3/E5 and everything you need certificates for is Intune-managed: Analyze the ratio. If more than about 60% of your user base is on E5, Cloud PKI is probably still worth it. If less than 40% is on E5, keep ADCS and use it for everyone. In between, run the specific numbers for your environment.

If you have any of the non-Intune scenarios (Linux, network gear, S/MIME, code signing, IoT, compliance-driven on-prem CA requirements): ADCS isn't going anywhere. Either keep it as your primary and use Cloud PKI for the specific subset of Intune-managed workloads where it adds value, or accept that you're running a hybrid infrastructure and budget accordingly.

If your PKI is currently unhardened and unmonitored: The Cloud PKI conversation is a distraction. Fix your ADCS security posture first. A Cloud PKI migration on top of a fragile on-prem PKI creates a hybrid infrastructure with two fragile halves. Get the on-prem side right, then decide whether Cloud PKI adds value on top.

Closing

Cloud PKI is a legitimately good product for a specific set of scenarios. The July 1 change makes it materially cheaper for E5 customers, which is real news worth planning around. The marketing narrative that Cloud PKI "retires your CA" is only true for a narrow set of enterprises whose PKI requirements are simple enough to fit inside Intune's model.

For everyone else, Cloud PKI joins ADCS in the infrastructure. It doesn't replace it.

The honest question in 2026 isn't "should I move to Cloud PKI." It's "which of my certificate use cases fit Cloud PKI, and which will always need ADCS, and can I make both work without doubling my operational cost."

The math on the Windows Server licenses is easy. Every other number is where the actual decision lives.