The simple answer is "no". Only CA role is registered in AD, thus CAs support auto-discovery. Other ADCS roles are not registered and doesn't support auto-discovery.
Locate servers with Certificate Authority Web Enrollment and Certificate Enrollment Web Service roles
![](https://techprofile.blob.core.windows.net/images/WbZ73xmXa0WFiQY-0ysEew.png?8D9929)
Mishaua
716
Reputation points
Is there a command to see servers with Certificate Authority Web Enrollment and/or Certificate Enrollment Web Service roles? I see that certutil.exe has a "Web Enrollment Servers" section is that where servers with the "Certificate Enrollment Web Service" should be listed? How about "Certificate Authority Web Enrollment"?
2 answers
Sort by: Most helpful
-
-
Mishaua 716 Reputation points
2022-10-20T19:39:46.217+00:00 I guess you could query ad for computers that have delegation enabled on the computer object to narrow down the roles. What roles besides "Certificate Authority Web Enrollment" require the computer account to have delegation enabled?