Skip to main content

This browser is no longer supported.

Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.

Download Microsoft Edge More info about Internet Explorer and Microsoft Edge
Read in English Edit

Share via

Facebook x.com LinkedIn Email

Active Directory Certificate Services documentation

Active Directory Certificate Services (AD CS) provides public key infrastructure (PKI) for cryptography, digital certificates and signature capabilities.

About Active Directory Certificate Services

What's new

  • What's New in Active Directory Certificate Services?

Overview

  • What is Active Directory Certificate Services?

Get started

Concept

  • Certification Authority role service
  • Certification Authority Web Enrollment
  • Certificate Enrollment Web Service
  • Certificate Enrollment Policy Web Service
  • Network Device Enrollment Service

How-To Guide

  • Configure Network Device Enrollment Service to use a domain user account
  • Disable weak cryptographic algorithms
  • Migrate a Certification Authority key to a Key Storage Provider
  • Configure trusted root and disallowed certificates
  • Use a policy module with Network Device Enrollment Service
  • Key-based certificate renewal
  • Perform a Delegated Installation for an Enterprise Certification Authority

More information

Training

  • Implement and manage Active Directory Certificate Services
  • Deploying an AD CS Two-Tier PKI Hierarchy

Reference

  • ADCSAdministration PowerShell module
  • ADCSDeployment PowerShell module
en-us
Your Privacy Choices
  • AI Disclaimer
  • Previous Versions
  • Blog
  • Contribute
  • Privacy
  • Terms of Use
  • Trademarks
  • © Microsoft 2025