Certificate Auto-Enrolment not starting

Michael Hathaway 21 Reputation points
2023-06-26T15:59:43.6266667+00:00

Hi Folks,

I have a strange issue, I have enabled the certificate services client to auto-enrol users and machines for certificates, manual enrolment works just fine, however when I try to force auto-enrolment with gpupdate /force, I do not see anything in the event viewer to say that the CertificateServicesClient attempted to enrol, all I see is that Group Policy has been applied successfully.

Does anyone have any pointers that I can try to see what is preventing the enrolment??

I have checked permissions on the templates and enrol and autoenroll are enabled for domain user and domain computers and authenticated users have the read permission.

If I run CertReq -v -AutoEnroll -machine or CertReq -v -AutoEnroll -user I am told that there are no certificate types available, which points me back to permissions??

Any ideas??

Thanks

Mike

Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. S.Sengupta 24,636 Reputation points MVP
    2023-06-27T00:37:41.68+00:00

    Certificate templates are stored on DCs not CA server, please check AD replication is working fine by running repadmin /showrepl and repadmin /replsum.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.