azure active directory domain service with PKI

testuser7 271 Reputation points
2022-03-17T19:01:29.71+00:00

I have spun an "Azure-Active-directory Domain Service"

Now I am standing up "Enterprise CA" server role on one the Windows Server VM that is joined to this AAD-DS

Is the design possible ?

Can I use AAD-DS with my PKI infrastructure ?
OR

I have to spin up self-service Active Directory ?

Thanks

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,909 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,595 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,586 Reputation points
    2022-03-17T21:01:29.443+00:00

    Hi,

    If you want install Enterprise CA , you have to installed on server member of a active directory domain:

    184301-image.png

    You can install Standalone CA , to avoid installing new domain for Enterprise CA.

    Please don't forget to mark helpful reply as answer


  2. Tobi Kr 26 Reputation points
    2023-01-22T20:45:24.5366667+00:00

    @VEIRMAN Loic AAD-DS does exist (Azure AD Directory Services) and it does not support Enterprise CA due to the limited permissions you will get as AAD-DS Admin