Review AD CS Certificate Template Enrollment Exposure
Active Directory Certificate Services (AD CS) connects certificate templates, enrollment permissions, and certificate authorities to domain identities. This focused, read-only review records published templates, CA-level request permissions, and template settings to identify who can enroll and what identities a template can represent.
This is a read-only audit for an authorized directory. Do not request test certificates or modify templates during inventory. Coordinate remediation with the PKI owner because changes can affect authentication and device enrollment.
Enumerate Enterprise CAs and Published Templates
PKI InventoryUse the Certification Authority console or built-in utilities to list reachable enterprise CAs and templates published by each CA. Record the CA name and host; a template that exists in the forest but is not published by a CA is not currently enrollable through that CA.
certutil -config - -pingcertutil -config "ca01.corp.example\Corp Issuing CA" -catemplates⯠View Expected Console Output
Connecting to ca01.corp.example\Corp Issuing CA ...ICertRequest2 interface is aliveTemplate list returned
Figure 1: Record the issuing CA and templates before evaluating enrollment exposure.
Inspect CA Permissions and Template Controls
CA and Template ReviewIn the Certification Authority console, open CA Properties > Security and record principals with Request Certificates or Manage CA rights. Then open Certificate Templates with certtmpl.msc and review template enrollment permissions, EKUs, issuance requirements, and subject-name settings. A requester generally needs both CA-level request access and template Enroll permission.
Review the CA:Security: Request Certificates, Manage CA, Issue and Manage CertificatesReview each published template:Security: Read, Enroll, Autoenroll, Write, Write OwnerSubject Name: Build from Active Directory or Supply in the requestExtensions: Application Policies / EKUsIssuance Requirements: approval and authorized signatures⯠View Expected Console Output
Template: Workstation AuthenticationEnroll: Domain ComputersSubject name: Built from Active DirectoryEKU: Client AuthenticationValidate Permission and Template Settings Together
Exposure AnalysisRequester-supplied subject names deserve priority review when ordinary users can enroll and a certificate can authenticate as a client, especially without approval or signature controls. Validate each combination with the PKI owner before assigning severity.
Record: CA and templateEnrollment principals:Subject-name source:Authentication-capable EKUs:Approval / signature controls:Owner and evidence:⯠View Expected Console Output
Assess the complete template configuration and issuing CA impact.Preserve Evidence and Agree on a Change Plan
Remediation PlanningAttach the CA security ACL, template publication state, template ACL, and effective enrollment groups to each finding. Consider reducing enrollment rights, removing unneeded EKUs, requiring approval, or changing subject handling only after dependency review.
finding | CA/template | evidence | owner | approved change | validation⯠View Expected Console Output
Audit complete: inventory captured; no CA or template settings changed.