Skip to content

Compatible with account required

Microsoft AD CS

Microsoft AD CS is implemented through a Windows agent: template discovery, SCEP/CES enrollment, renewal and private-key custody on the customer host. The control plane never stores AD credentials in logs.

Verification: test_verified. Connection: unknown. Credentials: none. Live E2E: no.

No AD CS lab or WinRM service account is configured.

What sslcertificates.io can do

Microsoft AD CS is implemented through a Windows agent: template discovery, SCEP/CES enrollment, renewal and private-key custody on the customer host. The control plane never stores AD credentials in logs. Capabilities: scep, cep, template_discovery, enroll, renew. Authentication uses winrm.

Required permissions

A constrained service account that can enroll the selected template. WinRM over TLS with pinned host key.

Setup

Open Dashboard → Integrations → Microsoft AD CS. Enter the credentials described on this page. Values are encrypted at rest and never shown again. Run Test connection. Discovery runs only after authentication succeeds. Select a discovered resource. Do not paste opaque IDs unless the provider cannot enumerate them. Perform the certificate or notification action, then confirm the external system matches. Disconnect removes stored credentials and owned test resources created by sslcertificates.io.

Known limitations

AD CS has no public REST API. Enrollment uses CEP/CES/SCEP or the Windows agent. Live E2E needs a domain-joined lab.

Official sources

Fact checked 2026-09-20. https://learn.microsoft.com/windows-server/identity/ad-cs/active-directory-certificate-services-overview Microsoft AD CS is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.

Capabilities

scep cep template_discovery enroll renew

Connect

Create an account to connect

Microsoft AD CS is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.