How can I authenticate to Windows Active Directory using a Certificate

Charlie Melga 126 Reputation points
2021-07-19T16:06:04.863+00:00

Hello

Can someone please answer the following for me, I understand how AD works and Kerberos

What I do not understand is how can I authenticate the Windows Active Directory using an Certificate (e.g. Client Authentication X509 cert) rather than a username and password?

Also once authenticated using a certificate will I get a TGT back?

Are there any utilities I can use to test this?

Thanks very much
CXMelga

Windows for business Windows Client for IT Pros Directory services Active Directory
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2021-07-20T03:57:23.11+00:00

    Hello @Charlie Melga ,

    Thank you for posting here.

    For Certificate authentication to Windows Active Directory, you need CA (Windows CA or non-Windows CA or third-party CA) server, certificates and smart card.

    For more information, please refer to link below.

    Guidelines for enabling smart card logon with third-party certification authorities
    https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/enabling-smart-card-logon-third-party-certification-authorities

    ADCS Step by Step Guide: Single Tier PKI Hierarchy Deployment
    https://social.technet.microsoft.com/wiki/contents/articles/11750.adcs-step-by-step-guide-single-tier-pki-hierarchy-deployment.aspx

    AD CS Step by Step Guide: Two Tier PKI Hierarchy Deployment
    https://social.technet.microsoft.com/wiki/contents/articles/15037.ad-cs-step-by-step-guide-two-tier-pki-hierarchy-deployment.aspx

    Hope the information above is helpful to you.

    Should you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.