News Date: 2026-10-08
Microsoft is warning security leaders that preparing for quantum-resistant authentication will require considerably more than replacing a cryptographic algorithm. The company recommends that organizations begin mapping and testing the extensive certificate ecosystems that establish trust across applications, devices, networks and cloud services.
Authentication Is an Ecosystem Problem
Much of the post-quantum security debate has focused on the risk that adversaries could collect encrypted information today and decrypt it when sufficiently capable quantum computers become available. Authentication presents a different operational challenge because certificates must be issued, distributed, stored, renewed and validated across products from many vendors.
Enterprises may know where TLS encrypts their communications but still lack a complete record of systems that depend on certificates. Those hidden dependencies can include internal public key infrastructure, hardware security modules, embedded equipment, operational technology, inspection appliances, custom software and long-lived devices that are difficult to upgrade.
Post-quantum certificates and certificate chains may also be larger than their current counterparts. That can affect handshake performance, storage, network transmission, traffic inspection and applications built around fixed assumptions about certificate size or supported algorithms.
Microsoft's Controlled Pilot
Microsoft's Post-Quantum Cryptography TLS Pilot Program allows approved certificate authorities to test roots and certificate issuance using ML-DSA-87. The certificates are not publicly trusted and are intended only for closed test environments, custom applications and enterprise laboratories.
Seven pilot roots were initially added for participating certificate authorities, including DigiCert, Sectigo, IdenTrust Services and SSL.com. Supported and properly configured Windows 11 systems can evaluate the certificates in approved non-production scenarios, providing an opportunity to test Windows, Schannel, certificate authorities and enterprise applications together.
Recommended First Steps
- Inventory systems that issue, store or validate certificates.
- Map public and private trust relationships.
- Ask PKI, software and hardware vendors for post-quantum roadmaps.
- Prioritize infrastructure with long replacement cycles.
- Build isolated test environments and document failures.
- Create a multi-year migration program with named owners.
In my view, organizations should approach this transition as an asset-discovery and dependency-management exercise. The cryptography may be standardized, but unknown legacy systems are likely to create the most expensive failures. Early testing gives enterprises time to replace incompatible components without turning a future migration into an emergency.
