Auto-Enrollment Policies
Active Directory Certificate Services (ADCS) auto-enrollment streamlines certificate issuance by automating the enrollment process for users, computers, and services. Auto-enrollment policies define how and when certificates are provisioned, ensuring alignment with organizational security requirements. These policies are configured at the certificate template level and can be managed via the Certification Authority (CA) console or Group Policy (GPO). This section explores the core policies governing auto-enrollment and their application across common certificate scenarios.
Auto Enrollment Policies¶
Certificate Template Configuration¶
Auto-enrollment is enabled or disabled per certificate template. Key policies include:
- Enrollment Flags: Control how certificates are issued (e.g., Enroll without user interaction, Require user approval).
- Auto-Enrollment Settings: Define whether the template is eligible for auto-enrollment and specify the scope (e.g., users, computers, or services).
- Subject Name Format: Determines how the certificate’s subject is populated (e.g., User Principal Name, DNS Name).
Example: To enable auto-enrollment for a user certificate template:
Set-CATemplate -Name "UserCertificate" -AutoEnrollmentEnabled $true -EnrollmentFlags "EnrollWithoutUserInteraction"
Group Policy Integration¶
GPOs can enforce auto-enrollment settings across the domain. The Computer Configuration > Policies > Administrative Templates > System > Certificate Services Client > Auto-Enrollment section allows:
- Specifying allowed certificate templates.
- Enabling/disabling auto-enrollment for users or computers.
- Configuring enrollment flags for specific scenarios (e.g., smart card logon).
Example: To enforce auto-enrollment for a specific template via GPO:
Set-GPRegistryValue -Name "AutoEnrollPolicy" -Key "HKLM\SOFTWARE\Policies\Microsoft\Cryptography\AutoEnrollment" -ValueName "AllowedTemplates" -Type MultiString -Value "UserCertificate"
Use Cases and Scenarios¶
1. User Certificate Auto-Enrollment¶
- Scenario: Enabling email encryption or S/MIME for users.
- Policy Requirements:
- Certificate template must include
User Principal Nameas a subject name. - Auto-enrollment must be enabled with
EnrollWithoutUserInteractionfor silent issuance. - GPOs may restrict templates to approved types (e.g.,
User Email Certificate).
2. Computer Certificate Auto-Enrollment¶
- Scenario: Securing communication between servers (e.g., HTTPS, LDAP).
- Policy Requirements:
- Template must include
DNS NameorIP Addressas the subject. - Auto-enrollment is typically enabled by default for computer accounts.
- Enrollment flags may require
EnrollWithoutUserInteractionfor server-side automation.
3. Code Signing Certificate Auto-Enrollment¶
- Scenario: Signing software or scripts to ensure authenticity.
- Policy Requirements:
- Template must include
Code Signingas a permitted usage. - Auto-enrollment is often disabled by default; manual enrollment is preferred for audit control.
- GPOs may restrict access to specific user groups (e.g., developers).
4. Smart Card Auto-Enrollment¶
- Scenario: Enabling two-factor authentication with smart cards.
- Policy Requirements:
- Template must include
Smart Card Logonas a permitted usage. - Auto-enrollment must be configured with
EnrollWithUserInteractionto prompt users for smart card credentials. - GPOs enforce smart card policies and certificate template restrictions.
Key takeaways¶
- Auto-enrollment policies are defined per certificate template and managed via CA console or GPO.
- User, computer, and code signing certificates require distinct configuration settings (e.g., subject name formats, enrollment flags).
- Group Policy enforces consistency across the domain, restricting allowed templates and enrollment behaviors.
- Smart card scenarios demand user interaction, while server-side certificates often use silent enrollment.