Skip to content

Auto-Enrollment

Active Directory Certificate Services (AD CS) enables auto-enrollment for user and computer certificates to automate certificate request and renewal processes. This reduces administrative overhead and ensures continuous certificate availability. Auto-enrollment relies on Group Policy (GPO), registry settings, and certificate template configurations. Below are steps to enable and configure auto-enrollment for user and computer certificates.


Enabling Auto Enrollment for User Certificates

1. Configure Group Policy

Auto-enrollment for user certificates is controlled via GPO. Follow these steps: 1. Open the Group Policy Management Console (GPMC). 2. Create or edit a GPO linked to the target OU. 3. Navigate to Computer Configuration > Policies > Administrative Templates > System > Certificates > Auto Enrollment. 4. Enable the "Auto enrollment of user certificates" policy. 5. Set the "Auto enrollment mode" to: - Enroll, Renew, Reenroll (default, for all certificate types) - Enroll, Renew (only for initial enrollment and renewal) 6. Click OK and close the GPO editor.

2. Configure Certificate Templates

Ensure the certificate template is configured for auto-enrollment: 1. Open the Certification Authority (CA) management console. 2. Right-click the certificate template and select Properties. 3. Go to the Security tab. 4. Add the "Auto Enrollment" flag to the certificate template. This flag must be explicitly configured in the CA to enable automatic enrollment and renewal for the template.

3. Verify with PowerShell

Use the Get-GPResultantSetOfPolicy cmdlet to confirm GPO application:

Get-GPResultantSetOfPolicy -PolicyName "Your GPO Name" -User <username>


Enabling Auto Enrollment for Computer Certificates

1. Configure Group Policy

  1. Open the GPMC and edit the target GPO.
  2. Navigate to Computer Configuration > Policies > Administrative Templates > System > Certificates > Auto Enrollment.
  3. Enable "Auto enrollment of computer certificates".
  4. Set the "Auto enrollment mode" as needed (e.g., Enroll, Renew).
  5. Click OK and close the GPO editor.

2. Configure Registry Settings (Optional)

For granular control, modify the registry: - User auto-enrollment:
HKLM\Software\Policies\Microsoft\Cryptography\AutoEnrollment
Set AutoEnrollmentEnabled to 1 and AutoEnrollmentMode to 0 (Enroll, Renew, Reenroll). - Computer auto-enrollment:
HKLM\Software\Policies\Microsoft\Cryptography\AutoEnrollment\Computer
Set AutoEnrollmentEnabled to 1 and AutoEnrollmentMode to 0.

3. Verify with PowerShell

Check the registry settings:

Get-ItemProperty -Path "HKLM:\Software\Policies\Microsoft\Cryptography\AutoEnrollment"


Troubleshooting Tips

  • Event Logs: Check Event Viewer > Windows Logs > Security for enrollment errors (e.g., Event ID 4114).
  • Permissions: Ensure the certificate template allows auto-enrollment for the target users/computers.
  • Certificate Templates: Verify the template is published and enabled in the CA.

Key takeaways

  • Auto-enrollment for user and computer certificates requires GPO or registry configuration.
  • Certificate templates must be set for auto-enrollment and properly published.
  • Use PowerShell and certutil to verify settings and troubleshoot enrollment failures.
  • Always test changes in a non-production environment before deploying widely.