Share via

User Autoenrollment

Applies To: Windows Server 2003 with SP1

This section illustrates manually pulsing autoenrollment and smart card enrollment.

Key Points

User autoenrollment for a smart card requires mandatory manual steps and user interaction, unlike other certificate types. Once autoenrollment has been enabled, the user will receive an informational balloon on the taskbar at the next Group Policy pulse interval (default of eight hours) or at the next logon.

Manually Pulsing Autoenrollment

Autoenrollment may be pulsed manually through the Certificates MMC snap-in.

To manually trigger autoenrollment

  1. Log on to the domain with the appropriate user account.

  2. Click the Start button, and then click Run.

  3. Type mmc.exe, and press ENTER.

    An empty MMC shell starts.

  4. Select the File menu, and then select Add/Remove Snap-In.

    A dialog box appears with a list of the snap-ins that have been added to the MMC shell.

  5. Click Add.

    A list of the registered snap-ins on the current machine appears.

  6. Double-click the Certificates snap-in, select My User Account, and then click Finish. If enrolling the machine for a certificate, such as a domain controller or a Web server, select Computer account.

  7. Click Next.

  8. Select Local Computer, and then click Finish.

  9. In the Add Standalone Snap-in dialog box, click Close. In the Add/Remove Snap-in dialog box, click OK.

    The MMC now contains the personal certificate store for the user.

  10. Right-click the top of the tree on CertificateCurrent User, select All Tasks on the context menu, and then select Automatically Enroll Certificates (Figure 9).

    Art ImageFigure 9: Automatically Enrolling Certificates


    It will take approximately one minute for the Certificate Enrollment balloon to be displayed, unless the registry key mentioned previously has been set. (See Balloon User Interface.)

Smart Card Enrollment

  1. Click the balloon or the corresponding certificate icon in the notification area once the Certificate Enrollment balloon is displayed. After a short period of time, the balloon will automatically disappear, and only the icon in the notification area will remain. After clicking the balloon, the Autoenrollment UI will start.


    The certificate enrollment balloon and wizard are not only for smart card enrollment but also for self-registration authority.

  2. Click the Start button (Figure 10).

    The wizard will begin. (The Remind Me Later button will cause the Certificate Enrollment balloon to re-appear at the next Group Policy pulse interval or the next interactive logon.)

    Art ImageFigure 10: Begin Enrolling Certificates

  3. If a smart card with the required CSP on the certificate is not inserted in the smart card reader, the user will be prompted to insert a smart card. Insert the smart card and click OK.


    If the certificate template on the users machine contains more than one CSP, the user may have to cycle through the wizard to reach the desired smart card CSP.

  4. If the displayed smart card CSP is not the desired CSP, click Cancel.

    The next CSP listed in the certificate template will be displayed.

  5. After inserting an appropriate smart card, click OK.

    The wizard will continue.


    If the smart card contains a private key and certificate in Slot0 (default container), the user will be warned about replacing the credentials on the smart card.


    Due to limitations with the smart card CSPs, smart card logon with both Windows 2000 and Windows XP requires that Slot0, or the default container on the card, be used to hold the certificate and private key used for smart card logon. If the card contains multiple keys and certificates, the last generated key and certificate will be marked as the default container on the card.

  6. If it is desired to replace the credentials on the smart card, click Yes (Figure 11).

    The wizard will continue (Figure 12).

    (The following is only one example of the dialog box a user may see. The smart card UI varies depending on the CSP being used.)

    Art ImageFigure 11: Replacing Credentials Dialog Box

    Art ImageFigure 12: Enrolling Certificates

  7. If a PIN is necessary for the smart card, a dialog box will be displayed. Enter the appropriate PIN and click Enter.

    Enrollment completes.


    If you enter the PIN incorrectly, the number of times you can retry will be limited.

    The success or failure of the autoenrollment process will be logged in the Application event log on the local computer. Also, a summary dialog box will appear for failed certificate requests that involved user interaction. If a failure occurs during enrollment, the user will be notified of the failure (Figure 13).

    Art ImageFigure 13: Notifying the User of Errors While Enrolling Certificates


    Users are not prompted when enrollment succeeds.