235 questions with Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI) tags

Sort by: Updated
1 answer

Windows Server 2025 AD CS certsrv.msc displays random Unicode characters in empty rows after Refresh

Environment: Windows Server 2025 (24H2) updated July 2026 ISO image Active Directory Certificate Services installed Certification Authority MMC snap-in (certsrv.msc) Issue: After adding a certificate request (Pending Requests / Issued Certificates…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-08-07T19:24:10.44+00:00
Sebastian 0 Reputation points
answered 2026-08-07T21:44:52.86+00:00
Allan Solomon Mejia 2,595 Reputation points
1 answer

Using RSA Token for RDP instead of Windows password

I am currently trying to configure our rdp sessions to prompt for RSA instead of a windows password, I tried registry edits and local GPO, is there something I'm missing, I assumed this would be a simple setup

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-08-06T15:25:18.6666667+00:00
Johnny 0 Reputation points
answered 2026-08-07T01:23:59.74+00:00
Allan Solomon Mejia 2,595 Reputation points
0 answers

Adding new OCSP online responder server to already running array controller.

I'm in a process of adding a newly build server running on windows 25 as a array member directly from array controller but repeatdely getting error RPC server not available. Want to know the ports and protocal involved in adding a newly build OCSP server…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-08-06T04:27:59.4133333+00:00
Aditya Singh 0 Reputation points
1 answer

Certificate Error - Subject Alternative Name

Dear, We are receiving the following message/error!!!. It is a Default Web Site in a IIS. In different forums, it is indicated that the error is because the URL names to be resolved in the certificate do not match. How do we verify this on the…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-07-31T19:15:32.95+00:00
Lucas Peñaloza 571 Reputation points
commented 2026-08-06T02:47:53.41+00:00
Lucas Peñaloza 571 Reputation points
1 answer One of the answers was accepted by the question author.

Safe PKI Issuing CA OS Migration (2019 to 2022): Backup/Restore Strategy Without Deleting Old CA First

Hi Everyone, I am planning an in-place upgrade/migration of an Active Directory-Integrated Enterprise Issuing CA running on Windows Server 2019 to a new Windows Server 2022 virtual machine. Key Requirements & Constraints: Quick Rollback: I want…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-07-28T07:16:47.07+00:00
Sreeram Raju 40 Reputation points
commented 2026-08-04T00:16:06.7266667+00:00
Steven Nguyen (WICLOUD CORPORATION) 415 Reputation points Microsoft External Staff Moderator
1 answer

Can a single NDES server support multiple certificate templates?

Hello Team, My internal PKI team mentioned that a Network Device Enrollment Service (NDES) server can only be configured to issue one certificate template, and that supporting multiple templates on a single NDES instance isn't possible. Is this statement…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-07-30T05:20:39.4266667+00:00
Sreeram Raju 40 Reputation points
answered 2026-07-30T07:01:22.6066667+00:00
Ivy Bui (WICLOUD CORPORATION) 510 Reputation points Microsoft External Staff Moderator
1 answer One of the answers was accepted by the question author.

Do I need to renew/re-sign the Issuing CA certificate after changing CDP/AIA URLs?

Hello, I have a Microsoft two-tier PKI with the following architecture: Offline Root CA Enterprise Issuing Subordinate CA I am changing the PKI architecture by adding a dedicated IIS server that will host: CRL Distribution Points (CDP) Authority…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-07-29T11:12:51.83+00:00
Yassine El Yakoubi 20 Reputation points
commented 2026-07-30T06:29:53.91+00:00
Yassine El Yakoubi 20 Reputation points
1 answer

Server 2022 certificate logon fails with "hash algorithm not supported on server"

Hi, I have a Windows Server 2022 in our domain where I want do log onto via RDP. Authentication should be handled via smartcard/certificate. The certificate was created as a smartcard certificate on the local CA which is trusted by the server. Whenever I…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-07-27T10:18:53.47+00:00
Stefan Strasser 0 Reputation points
commented 2026-07-30T06:23:53.2+00:00
Stefan Strasser 0 Reputation points
1 answer

Work Folders sync failing with sync relationship error

When a subset of users tries to sync Work Folders, they cannot access the sync options because it fails with "sync relationship could not be established." What's the certificate / AD FS dependency check for Work Folders?

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-07-28T17:27:41.7033333+00:00
David Brown 0 Reputation points
answered 2026-07-28T20:02:17.2866667+00:00
Allan Solomon Mejia 2,595 Reputation points
3 answers One of the answers was accepted by the question author.

Cert private key permission changes

Hello, We're implementing a new Windows Event Collector using HTTPS. I have followed various online guides from Microsoft and others and I have a working environment. The only issue I ran in to was having to assign the NETWORK SERVICE account read only…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-04-13T19:13:26.4+00:00
Hardwick, Lewis 20 Reputation points
answered 2026-07-27T15:26:24.8266667+00:00
Joseph Miller 0 Reputation points
1 answer One of the answers was accepted by the question author.

ADFS Token-Signing Cert Expired (Auto-rollover bypassed) / Need safe manual rollover steps

Hi team, We have a P1 incident on ADFS. The automated token-signing certificate rollover failed to trigger, and current cert is already expired. Federated login for all integrated apps is currently down. We need to execute a manual certificate renewal…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-07-16T06:49:22.2333333+00:00
Lyn 60 Reputation points
accepted 2026-07-20T16:56:11.3533333+00:00
Lyn 60 Reputation points
1 answer One of the answers was accepted by the question author.

802.1x certificate revoke

We use certificate for 802.1x to access to the internal network. Let say one device is stolen then i know i can revoke the certificate from Microsoft CA, but how this is work? I mean after certificate revoked then my radius is aware that certificate was…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-07-07T03:49:29.0566667+00:00
Handian Sudianto 7,361 Reputation points
accepted 2026-07-07T08:34:30.4766667+00:00
Handian Sudianto 7,361 Reputation points
3 answers

What security settings are required to make an x.509 certificate that is bound to a windows trusted platform manager key usable for all users (who will not have admin rights)?

My application is using .net 8. I'm using System.Security.Cryptography.CngKey object to create the a TPM key (using elevated local admin credentials). Using this key, I can create an x.509 certificate signing request without issue. I can bind the…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-06-24T19:15:56.5333333+00:00
Erickson, Blair M 0 Reputation points
commented 2026-06-30T15:20:10.7233333+00:00
Erickson, Blair M 0 Reputation points
1 answer

USER_NOT_FOUND ADCS

I'm about at my wit ends with an issue and need some help. Some background: We have a enterprise PKI set-up with an offline root, and two online subordinate issuing CAs. Workstations and servers trust these certs and can auto enroll without issue. We…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-06-26T09:26:03.3+00:00
Chris W 0 Reputation points
answered 2026-06-26T10:27:04.22+00:00
Domic Vo 28,365 Reputation points Independent Advisor
1 answer

AD CS autoenrollment - what makes the client renew a still-valid, OID-matching cert when the template's major version never changes?

Setup: Enterprise CA, version 2 certificate template, machine autoenrollment via GPO with "Update certificates that use certificate templates" enabled. The certificate is matched to the template by OID. Behavior: A machine certificate is issued…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-06-22T20:54:12.66+00:00
Danish Joshi 0 Reputation points
answered 2026-06-22T22:22:16.8133333+00:00
Domic Vo 28,365 Reputation points Independent Advisor
4 answers

Upgrade Order ADDS and ADCS

I'm currently running two 2012 R2 domain controllers and a 2012 R2 root CA. I’m planning to upgrade both ADDS and ADCS to Server 2022, and I want to replace the current root CA with a 2-Tier PKI setup. My question is: which one should I upgrade first,…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-06-16T17:01:05.4566667+00:00
Wai Yan Oo 0 Reputation points
answered 2026-06-20T05:30:33.1166667+00:00
VPHAN 42,480 Reputation points Independent Advisor
1 answer

Windows Server 2025 blocking "Server Hello" package from localhost self-signed HTTPS web service

Hello, I have successfully installed a standalone web server (Siemens Gridpass) on my Windows Server 2025 VM. When I did the installation on a normal Windows 11 VM, the software worked fine. During the installation the software creates a new local user…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-06-17T10:46:36.89+00:00
Sieber, Patrick Hristo 0 Reputation points
answered 2026-06-17T11:36:04.4866667+00:00
Jason Nguyen Tran 24,530 Reputation points Independent Advisor
2 answers

how do i get a new secure boot certificate

Hello I need a new secure boot certificate for Windows 10

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-06-12T17:26:20.3466667+00:00
Dennis Wilkinson 0 Reputation points
answered 2026-06-12T19:42:14.4033333+00:00
Scott Nguyen 1,965 Reputation points Independent Advisor
2 answers One of the answers was accepted by the question author.

Windows server 2016 RDP TLS /SSL certificate

I am reviewing the TLS/SSL certificate configuration used for remote desktop services on windows server 2016 VM and would like some help During the review of the remote desktop certificate . i observed a message "The root CA certificate is not…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-06-10T14:47:44.7633333+00:00
sara rashid 20 Reputation points
commented 2026-06-11T12:52:27.8566667+00:00
sara rashid 20 Reputation points
2 answers

Windows NPS with CA 802.1x wired

I am experiencing an issue with 802.1X authentication. This is the first user/computer attempting to authenticate in this setup. The environment consists of Windows 11 clients and Windows Server 2025. On the server side, NPS is configured with network…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-06-03T13:25:00.5166667+00:00
Paweł Wójcik 0 Reputation points
commented 2026-06-08T08:04:37.1433333+00:00
Paweł Wójcik 0 Reputation points