Share via

Azure AD Directory Services + Standalone CA + Auto Enrollment

Tobi Kr 26 Reputation points
2023-01-22T20:54:34.1133333+00:00

Hi!

I just deployed an AAD DS instance and joined some VMs. I also installed a certificate authority (standalone as enterprise is not available in AAD DS). Any idea how to enroll computer and/or user certificates for joined VMs and Users automatically?

Thanks

Tobias

Windows for business | Windows Server | Devices and deployment | Configure application groups
Microsoft Security | Microsoft Entra | Other
0 comments No comments

Answer accepted by question author
  1. Vadims Podāns 9,266 Reputation points MVP
    2023-01-23T08:31:45.08+00:00

    Unfortunately, automatic certificate enrollment and renewal is supported by Enterprise CA only. Moreover, Standalone CA doesn't support certificate templates, so you even cannot use Certificates MMC snap-in to directly enroll from Standalone CA.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Limitless Technology 45,226 Reputation points
    2023-01-24T09:29:33.52+00:00

    Hello Toby Kr,

    You can check this official article for a step by steops guide on both cases:

    https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-autoenrollment

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.