# Winlogbeat supports for TPM Windows certificates store

**URL:** <https://discuss.elastic.co/t/winlogbeat-supports-for-tpm-windows-certificates-store/386098>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 29, 2026, 2:57pm UTC](https://discuss.elastic.co/t/winlogbeat-supports-for-tpm-windows-certificates-store/386098 "2026-04-29T14:57:01Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![MiguelN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/migueln/32/147466_2.png) [@MiguelN](https://discuss.elastic.co/u/MiguelN)\
**Post date:** [April 29, 2026, 2:57pm UTC](https://discuss.elastic.co/t/winlogbeat-supports-for-tpm-windows-certificates-store/386098/1 "2026-04-29T14:57:01Z")

</div>

I want to deploy per-device client certificates to Windows workstations via Intune SCEP, with the private key generated and bound to the TPM (Microsoft Platform Crypto Provider, non-exportable). Winlogbeat would then use that cert for Kafka `output.kafka` mTLS, without ever exporting the key to disk.

A few questions:

1. Does Winlogbeat support referencing a client certificate directly from the Windows Certificate Store (e.g. `store://LocalMachine/My/<thumbprint>` or similar)? If so, what's the current supported syntax and from which version?

2. Does that path work with a **TPM-bound, non-exportable** private key? i.e., does Winlogbeat go through Schannel/CNG so the TPM handles signing, or does it expect raw key material it can read itself?

3. If TPM-bound keys aren't supported directly, is there a recommended pattern, or is Software KSP with an on-disk PFX the documented approach?

Filebeat version: 9.3.1

Thanks a lot in advanced!
