Can someone clarify the reason for needing a dedicated CA for SEMM? "It is also recommended that the SEMM certificate be authenticated in a two-tier public key infrastructure (PKI) architecture where the intermediate certification authority (CA) is dedicated to SEMM, enabling certificate revocation. For more information about a two-tier PKI configuration, see Test Lab Guide: Deploying an AD CS Two-Tier PKI Hierarchy."
The Article I pulled that quote from is:
https://docs.microsoft.com/en-us/surface/surface-enterprise-management-mode