Hello Handian,
For Intune-delivered 802.1X certificates that are issued from your internal Microsoft CA, renewal is handled through the SCEP or PKCS certificate profile you configured in Intune. As long as the profile is still assigned and valid, Intune will automatically request a new certificate from the CA before the current one expires. The renewal window is controlled by the CA template configuration. By default, Windows clients attempt renewal when 80% of the certificate lifetime has passed. For example, if the certificate validity is one year, renewal will start around the 9-10 month mark.
To ensure smooth renewal, you should verify two things. First, check the certificate template on your CA under Certification Authority > Certificate Templates. Confirm that “Renewal period” is set appropriately (for example, 2 months before expiration). Second, make sure the Intune profile is still active and assigned to the devices. If the template allows renewal and Intune continues to push the profile, the client will automatically request a new certificate from the CA without user intervention.
If you want to force a renewal earlier, you can manually delete the existing certificate from the user’s personal store (certmgr.msc > Personal > Certificates) and then trigger a sync from Intune (Settings > Accounts > Access work or school > Sync). The device will then request a fresh certificate from the CA via Intune.
In short, you don’t need to manually reissue certificates if the template and Intune profile are correctly configured. Just ensure the renewal period in the CA template is set to cover your 2‑month window, and Intune will handle the rest.
I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!
DV.