Running your own internal Certificate Authority sounds intimidating but is genuinely one of the more approachable AD-integrated roles once you understand the two-tier design Microsoft recommends: an offline root CA that almost never touches the network, and one or more online issuing CAs that actually hand out certificates day to day.
- A two-tier PKI (offline root + online issuing CA) is the recommended design even for small environments
- The root CA should be taken offline after setup and only brought online to renew the issuing CA’s certificate
- Certificate templates control what a certificate can be used for and who can request it
- Auto-enrollment via Group Policy is what makes AD CS actually useful at scale
Step 1: Build the offline root CA
Install AD CS on a standalone (non-domain-joined) VM or physical machine intended to stay offline most of the time:
Install-WindowsFeature ADCS-Cert-Authority -IncludeManagementTools
Configure it as a standalone root CA with a long validity period (typically 10-20 years), then shut it down once the root certificate is generated. It only needs to come back online occasionally to issue or renew the issuing CA’s certificate.
Step 2: Deploy the online issuing CA
On a domain-joined server, install AD CS again and configure it as an Enterprise Subordinate CA, submitting its certificate request to the offline root CA to get it signed. This issuing CA is what actually handles day-to-day certificate requests from domain-joined machines and users.
Step 3: Create and publish a certificate template
Duplicate an existing template (like “Computer” or “User”) rather than building from scratch, adjust the permissions and validity period, then publish it via the Certificate Templates console so the issuing CA offers it. Set autoenrollment permissions on the template for the groups that should receive it automatically.
Step 4: Enable auto-enrollment via Group Policy
Enable “Certificate Services Client – Auto-Enrollment” in a GPO linked to the relevant OUs, and computers/users matching your template’s permissions will request and renew certificates automatically without any manual intervention. This is where AD CS actually starts paying off operationally.
For official guidance, see Microsoft’s Windows Server documentation.
Gear We Recommend
Testing configs is easier with a dedicated admin machine set up right. Here’s the kit we use.
Browse our Windows Admin Toolkit picks on AmazonAs an Amazon Associate, TechyGeeksHome earns from qualifying purchases.
Discover more from TechyGeeksHome
Subscribe to get the latest posts sent to your email.