Skip to content

Auto-Enrollment Policies

Active Directory Certificate Services (ADCS) auto-enrollment streamlines certificate issuance by automating the enrollment process for users, computers, and services. Auto-enrollment policies define how and when certificates are provisioned, ensuring alignment with organizational security requirements. These policies are configured at the certificate template level and can be managed via the Certification Authority (CA) console or Group Policy (GPO). This section explores the core policies governing auto-enrollment and their application across common certificate scenarios.


Auto Enrollment Policies

Certificate Template Configuration

Auto-enrollment is enabled or disabled per certificate template. Key policies include: - Enrollment Flags: Control how certificates are issued (e.g., Enroll without user interaction, Require user approval). - Auto-Enrollment Settings: Define whether the template is eligible for auto-enrollment and specify the scope (e.g., users, computers, or services). - Subject Name Format: Determines how the certificate’s subject is populated (e.g., User Principal Name, DNS Name).

Example: To enable auto-enrollment for a user certificate template:

Set-CATemplate -Name "UserCertificate" -AutoEnrollmentEnabled $true -EnrollmentFlags "EnrollWithoutUserInteraction"

Group Policy Integration

GPOs can enforce auto-enrollment settings across the domain. The Computer Configuration > Policies > Administrative Templates > System > Certificate Services Client > Auto-Enrollment section allows: - Specifying allowed certificate templates. - Enabling/disabling auto-enrollment for users or computers. - Configuring enrollment flags for specific scenarios (e.g., smart card logon).

Example: To enforce auto-enrollment for a specific template via GPO:

Set-GPRegistryValue -Name "AutoEnrollPolicy" -Key "HKLM\SOFTWARE\Policies\Microsoft\Cryptography\AutoEnrollment" -ValueName "AllowedTemplates" -Type MultiString -Value "UserCertificate"


Use Cases and Scenarios

1. User Certificate Auto-Enrollment

  • Scenario: Enabling email encryption or S/MIME for users.
  • Policy Requirements:
  • Certificate template must include User Principal Name as a subject name.
  • Auto-enrollment must be enabled with EnrollWithoutUserInteraction for silent issuance.
  • GPOs may restrict templates to approved types (e.g., User Email Certificate).

2. Computer Certificate Auto-Enrollment

  • Scenario: Securing communication between servers (e.g., HTTPS, LDAP).
  • Policy Requirements:
  • Template must include DNS Name or IP Address as the subject.
  • Auto-enrollment is typically enabled by default for computer accounts.
  • Enrollment flags may require EnrollWithoutUserInteraction for server-side automation.

3. Code Signing Certificate Auto-Enrollment

  • Scenario: Signing software or scripts to ensure authenticity.
  • Policy Requirements:
  • Template must include Code Signing as a permitted usage.
  • Auto-enrollment is often disabled by default; manual enrollment is preferred for audit control.
  • GPOs may restrict access to specific user groups (e.g., developers).

4. Smart Card Auto-Enrollment

  • Scenario: Enabling two-factor authentication with smart cards.
  • Policy Requirements:
  • Template must include Smart Card Logon as a permitted usage.
  • Auto-enrollment must be configured with EnrollWithUserInteraction to prompt users for smart card credentials.
  • GPOs enforce smart card policies and certificate template restrictions.

Key takeaways

  • Auto-enrollment policies are defined per certificate template and managed via CA console or GPO.
  • User, computer, and code signing certificates require distinct configuration settings (e.g., subject name formats, enrollment flags).
  • Group Policy enforces consistency across the domain, restricting allowed templates and enrollment behaviors.
  • Smart card scenarios demand user interaction, while server-side certificates often use silent enrollment.