Configuring Certificate Services (AD CS) on Windows Server: A Beginner’s Guide

Running your own internal Certificate Authority sounds intimidating but is genuinely one of the more approachable AD-integrated roles once you understand the two-tier design Microsoft recommends: an offline root CA that almost never touches the network, and one or more online issuing CAs that actually hand out certificates day to day. A two-tier PKI (offline […]

Configuring Certificate Services (AD CS) on Windows Server: A Beginner's Guide

Running your own internal Certificate Authority sounds intimidating but is genuinely one of the more approachable AD-integrated roles once you understand the two-tier design Microsoft recommends: an offline root CA that almost never touches the network, and one or more online issuing CAs that actually hand out certificates day to day.

  • A two-tier PKI (offline root + online issuing CA) is the recommended design even for small environments
  • The root CA should be taken offline after setup and only brought online to renew the issuing CA’s certificate
  • Certificate templates control what a certificate can be used for and who can request it
  • Auto-enrollment via Group Policy is what makes AD CS actually useful at scale

Step 1: Build the offline root CA

Install AD CS on a standalone (non-domain-joined) VM or physical machine intended to stay offline most of the time:

Install-WindowsFeature ADCS-Cert-Authority -IncludeManagementTools

Configure it as a standalone root CA with a long validity period (typically 10-20 years), then shut it down once the root certificate is generated. It only needs to come back online occasionally to issue or renew the issuing CA’s certificate.

Step 2: Deploy the online issuing CA

On a domain-joined server, install AD CS again and configure it as an Enterprise Subordinate CA, submitting its certificate request to the offline root CA to get it signed. This issuing CA is what actually handles day-to-day certificate requests from domain-joined machines and users.

Step 3: Create and publish a certificate template

Duplicate an existing template (like “Computer” or “User”) rather than building from scratch, adjust the permissions and validity period, then publish it via the Certificate Templates console so the issuing CA offers it. Set autoenrollment permissions on the template for the groups that should receive it automatically.

Step 4: Enable auto-enrollment via Group Policy

Enable “Certificate Services Client – Auto-Enrollment” in a GPO linked to the relevant OUs, and computers/users matching your template’s permissions will request and renew certificates automatically without any manual intervention. This is where AD CS actually starts paying off operationally.

For official guidance, see Microsoft’s Windows Server documentation.

🛠️

Gear We Recommend

Testing configs is easier with a dedicated admin machine set up right. Here’s the kit we use.

Browse our Windows Admin Toolkit picks on Amazon

As an Amazon Associate, TechyGeeksHome earns from qualifying purchases.


Discover more from TechyGeeksHome

Subscribe to get the latest posts sent to your email.

Andrew Armstrong

Andrew Armstrong is a UK-based IT professional with 26+ years of hands-on experience in Windows, Windows Server, SCCM/ConfigMgr, Intune, Active Directory, PowerShell and enterprise infrastructure.

He founded TechyGeeksHome in 2010 and has published 770+ practical guides to real-world IT problems. He also builds free Windows utilities, including Ultimate Settings Panel, which has been downloaded over 850,000 times.