Skip to content

Review AD CS Certificate Template Enrollment Exposure

Active Directory Certificate Services (AD CS) connects certificate templates, enrollment permissions, and certificate authorities to domain identities. This focused, read-only review records published templates, CA-level request permissions, and template settings to identify who can enroll and what identities a template can represent.

This is a read-only audit for an authorized directory. Do not request test certificates or modify templates during inventory. Coordinate remediation with the PKI owner because changes can affect authentication and device enrollment.


01

Enumerate Enterprise CAs and Published Templates

PKI Inventory

Use the Certification Authority console or built-in utilities to list reachable enterprise CAs and templates published by each CA. Record the CA name and host; a template that exists in the forest but is not published by a CA is not currently enrollable through that CA.

Terminal window
certutil -config - -ping
certutil -config "ca01.corp.example\Corp Issuing CA" -catemplates
❯ View Expected Console Output
Connecting to ca01.corp.example\Corp Issuing CA ...
ICertRequest2 interface is alive
Template list returned
Certification Authority MMC showing an enterprise CA and its issued certificate templates

Figure 1: Record the issuing CA and templates before evaluating enrollment exposure.


02

Inspect CA Permissions and Template Controls

CA and Template Review

In the Certification Authority console, open CA Properties > Security and record principals with Request Certificates or Manage CA rights. Then open Certificate Templates with certtmpl.msc and review template enrollment permissions, EKUs, issuance requirements, and subject-name settings. A requester generally needs both CA-level request access and template Enroll permission.

Review the CA:
Security: Request Certificates, Manage CA, Issue and Manage Certificates
Review each published template:
Security: Read, Enroll, Autoenroll, Write, Write Owner
Subject Name: Build from Active Directory or Supply in the request
Extensions: Application Policies / EKUs
Issuance Requirements: approval and authorized signatures
❯ View Expected Console Output
Template: Workstation Authentication
Enroll: Domain Computers
Subject name: Built from Active Directory
EKU: Client Authentication

03

Validate Permission and Template Settings Together

Exposure Analysis

Requester-supplied subject names deserve priority review when ordinary users can enroll and a certificate can authenticate as a client, especially without approval or signature controls. Validate each combination with the PKI owner before assigning severity.

Record: CA and template
Enrollment principals:
Subject-name source:
Authentication-capable EKUs:
Approval / signature controls:
Owner and evidence:
❯ View Expected Console Output
Assess the complete template configuration and issuing CA impact.

04

Preserve Evidence and Agree on a Change Plan

Remediation Planning

Attach the CA security ACL, template publication state, template ACL, and effective enrollment groups to each finding. Consider reducing enrollment rights, removing unneeded EKUs, requiring approval, or changing subject handling only after dependency review.

finding | CA/template | evidence | owner | approved change | validation
❯ View Expected Console Output
Audit complete: inventory captured; no CA or template settings changed.

Comments