Active Directory Certificate Services roles and topology

Advanced
Administrator
Security Engineer
Windows Server

Turn business, assurance, availability, and boundary requirements into an Active Directory Certificate Services topology for Windows Server 2025.

Learning objectives

By the end of this module, you'll be able to:

  • Select the AD CS role services needed for each enrollment and validation population.
  • Choose enterprise or standalone CA operating models and an appropriate hierarchy depth.
  • Defend a protected offline root with one or more online enterprise issuing CAs as the usual production starting point.
  • Scale issuance and enrollment services without confusing service availability with CA identity or revocation availability.
  • Design across forest, extranet, domain, non-domain, and application trust boundaries.
  • Separate root trust, chain construction, Enterprise NTAuth authorization, and application-specific trust.
  • Place hardware security module (HSM) services and administrative roles according to assurance, availability, and recovery objectives.
  • Plan a controlled root ceremony and offline custody model.

Prerequisites

Before starting this module, you should have experience with:

  • Public key infrastructure design.
  • Active Directory Domain Services configuration partitions, replication, sites, and services.
  • Enterprise administrative tiers.
  • DNS, HTTP, LDAP, RPC/DCOM, Transport Layer Security (TLS), firewalls, and load balancing.
  • Backup and recovery concepts.