Microsoft CA Auto Enrollment

๐Ÿ”’ Secure Bits ๐Ÿ’ก
Weird ๐—ถ๐˜€๐˜€๐˜‚๐—ฒ๐˜€ ๐˜„๐—ถ๐˜๐—ต ๐—”๐˜‚๐˜๐—ผ ๐—˜๐—ป๐—ฟ๐—ผ๐—น๐—น๐—บ๐—ฒ๐—ป๐˜ in Microsoft CA? Hereโ€™s one that cost me hours.

I recently set up a ๐—ณ๐—ฟ๐—ฒ๐˜€๐—ต ๐—œ๐˜€๐˜€๐˜‚๐—ถ๐—ป๐—ด ๐—–๐—” on Windows Server 2025 in a brand-new Active Directory domain:
โœ”๏ธ Auto-enroll GPO? โœ…
โœ”๏ธ Certificate template published & configured for domain computers? โœ…
โœ”๏ธ ACLs set up? โœ…

๐—ฌ๐—ฒ๐˜ โ€” ๐—ป๐—ผ ๐—ฐ๐—ฒ๐—ฟ๐˜๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ. Not after a reboot. Not after waiting. Nothing.

After ๐—ต๐—ผ๐˜‚๐—ฟ๐˜€ ๐—ผ๐—ณ ๐˜๐—ฟ๐—ผ๐˜‚๐—ฏ๐—น๐—ฒ๐˜€๐—ต๐—ผ๐—ผ๐˜๐—ถ๐—ป๐—ด, I stumbled upon Uwe Gradeneggerโ€™s great blog:
๐Ÿ”— https://www.gradenegger.eu/en/the-request-for-a-certificate-fails-with-the-error-message-the-requested-certificate-template-is-not-supported-by-this-ca/

๐—›๐—ฒ๐—ฟ๐—ฒโ€™๐˜€ ๐˜„๐—ต๐—ฎ๐˜ ๐˜„๐—ฎ๐˜€ ๐˜„๐—ฟ๐—ผ๐—ป๐—ดย โฌ‡๏ธ
๐Ÿ’ฅ The ACL about who can actually request certificates ๐—ผ๐—ป ๐—–๐—” ๐—น๐—ฒ๐˜ƒ๐—ฒ๐—น was not synced.

๐—ฅ๐—ฒ๐—พ๐˜‚๐—ฒ๐˜€๐˜ ๐—–๐—ฒ๐—ฟ๐˜๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ๐˜€ ๐—”๐—–๐—˜ (๐—˜๐—ป๐—ฟ๐—ผ๐—น๐—น) ๐˜€๐—ต๐—ผ๐˜‚๐—น๐—ฑ ๐—ฏ๐—ฒ ๐—ถ๐—ป ๐˜๐˜„๐—ผ ๐—ฝ๐—น๐—ฎ๐—ฐ๐—ฒ๐˜€:
1๏ธโƒฃ The registry of the CA (you can see this in CA console)
2๏ธโƒฃ The Configuration partition in Active Directory (query this with certutil)

Somehow โ€” and I still donโ€™t know why โ€” the AD Config partition was ๐—บ๐—ถ๐˜€๐˜€๐—ถ๐—ป๐—ด the Request Certificates ACE (Enroll) for Authenticated Users.

โœ… Re-added the Read + Enroll rights
โœ… Waited a minute
โœ… Auto-enroll worked perfectly

Just wanted to share this with you โ€” in case you ever run into the same headache.