The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Inspect AD CS features | Get-WindowsFeature AD-Certificate,ADCS-Cert-Authority | View examples |
| Inspect domain context | Get-CimInstance Win32_ComputerSystem |
Select-Object Name,Domain,PartOfDomain | View examples |
| Install CA binaries | Install-WindowsFeature ADCS-Cert-Authority `
-IncludeManagementTools -WhatIf | View examples |
| Configure an enterprise subordinate CA | Install-AdcsCertificationAuthority -CAType `
EnterpriseSubordinateCA -CACommonName `
'Contoso Issuing CA 01' -WhatIf | View examples |
| Inspect CA service | Get-Service CertSvc | View examples |
| Read CA configuration | certutil.exe -getreg CA | View examples |
| List issued templates | Get-CATemplate | View examples |
| Publish a template | Add-CATemplate -Name 'ContosoWebServer' -WhatIf | View examples |
| Inspect pending requests | certutil.exe -view -restrict 'Disposition=9' -out `
'RequestID,RequesterName,CommonName' | View examples |
| Inspect issued requests | certutil.exe -view -restrict 'Disposition=20' -out `
'RequestID,CommonName,NotAfter' | View examples |
| Revoke a certificate | certutil.exe -revoke $Serial KeyCompromise | View examples |
| Publish a new CRL | certutil.exe -crl | View examples |
| Verify certificate URLs | certutil.exe -url '.\issued.cer' | View examples |
| Back up CA database and key | Backup-CARoleService -Path 'E:\CA-Backup' -Password `
(Read-Host -AsSecureString) | View examples |
| Export CA configuration | reg.exe export `
'HKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration' `
'.\ca-config.reg' /y | View examples |
| Read CA operational events | Get-WinEvent -LogName 'Application' -ProviderName `
'Microsoft-Windows-CertificationAuthority' -MaxEvents `
100 | View examples |
Active Directory Certificate Services is a long-lived trust system, not merely a server role. CA hierarchy, name, key protection, algorithms, validity, templates, issuance policy, revocation publishing, auditing, backup, and disaster recovery must be designed before installation. Most deployment actions are irreversible or disruptive without a migration, so examples emphasize inspection, staged plans, protected keys, and recovery drills rather than one-line production installation.
Step by step
Detailed examples
Design the PKI before installing the CA
Choose an offline standalone root and online enterprise issuing tier when organizational risk warrants it. Decide CA names, validity periods, algorithms, key sizes, HSM or KSP, database and log locations, AIA/CDP URLs, template governance, auditing, backup custody, and renewal strategy first; the CA name cannot simply be renamed later. Enterprise CAs require AD DS membership and permissions, while standalone CAs do not use templates. Verify supported Windows Server edition and role prerequisites, accurate time, DNS, and protected administrative access.
Get-ComputerInfo -Property WindowsProductName,WindowsVersion,OsBuildNumber
Get-CimInstance Win32_ComputerSystem | Select-Object Name, Domain, PartOfDomain
Get-WindowsFeature AD-Certificate, ADCS-Cert-Authority
Get-Tpm -ErrorAction SilentlyContinue | Select-Object TpmPresent, TpmReady Separate role installation from CA configuration
Installing ADCS-Cert-Authority adds binaries; Install-AdcsCertificationAuthority creates or joins the trust hierarchy. Run from an elevated Windows PowerShell session on a supported Windows Server. Enterprise CA deployment requires appropriate AD privileges and forest readiness. Review CAPolicy.inf before installation when defaults must change. WhatIf is useful but cannot model HSM prompts, AD publication, service startup, or every provider effect. Some role changes may request a restart; CA configuration starts CertSvc and creates sensitive keys and database state.
$Plan = @{
CAType = 'EnterpriseSubordinateCA'
CACommonName = 'Contoso Issuing CA 01'
CryptoProviderName = 'RSA#Microsoft Software Key Storage Provider'
HashAlgorithmName = 'SHA256'
KeyLength = 3072
}
Install-WindowsFeature ADCS-Cert-Authority -IncludeManagementTools -WhatIf
Install-AdcsCertificationAuthority @Plan -WhatIf Inspect local CA identity and service health
The ADCSAdministration module operates primarily on the local CA. Confirm which CA and registry path a session targets before acting. CertSvc restart interrupts enrollment and can delay publication, so schedule configuration changes. certutil is powerful and includes mutating verbs; pair exact documented switches with change approval. Monitor database space, log volume, service state, enrollment latency, CA certificate expiration, signing key health, and failed publication—not just whether the service is running.
Get-Service CertSvc | Select-Object Status, StartType, Name
certutil.exe -getreg CA
certutil.exe -getreg CA\CRLPublicationURLs
Get-ChildItem Cert:\LocalMachine\My |
Where-Object HasPrivateKey | Select-Object Subject, Thumbprint, NotAfter Govern templates in Active Directory and on the CA
Enterprise certificate templates are AD objects with version, cryptography, subject construction, application policies, validity, renewal, issuance requirements, and ACLs. Add-CATemplate only publishes an existing template on the CA; it does not safely design the template. Avoid enrollee-supplied subject or broad enrollment rights unless the complete authentication threat model supports them. Separate template managers, CA managers, and enrollment principals. Changes replicate through AD and can immediately affect autoenrollment at scale.
Get-CATemplate | Sort-Object Name | Format-Table Name
# Validate the AD template ACL, EKUs, subject rules, key export, and issuance policy separately.
# Approved CA change only:
# Add-CATemplate -Name 'ContosoWebServer' -WhatIf Verify certificate identity before approval or revocation
Pending approval is a security decision: validate requester identity, template, subject alternative names, intended usage, ownership, and policy evidence. Revocation is disruptive and does not erase a certificate; relying parties must receive a fresh CRL or OCSP response. Choose the truthful reason code, record the incident, and verify the exact serial or request ID. The built-in ADCSAdministration module does not expose CA database approval or revocation cmdlets; use the documented certutil verbs or the Certification Authority console. certutil has no WhatIf.
certutil.exe -view -restrict 'Disposition=9' `
-out 'RequestID,RequesterName,CommonName,CertificateTemplate,Request.SubmittedWhen'
certutil.exe -view -restrict 'Disposition=20' `
-out 'RequestID,RequesterName,CommonName,SerialNumber,NotAfter'
# certutil -resubmit, -deny, and -revoke mutate CA state; require independent review. Make revocation information continuously reachable
CRL distribution points and Authority Information Access paths are embedded into issued certificates, so a bad URL persists for their lifetime. Publish base and delta CRLs early enough to survive outages and monitor HTTP/LDAP retrieval from every relying network. certutil -crl publishes signed revocation data immediately and has no dry run; verify Next Update and replicate output to all configured distribution points. certutil -url provides an interactive retrieval check, while certutil -verify -urlfetch validates a chain using network retrieval.
Get-CACrlDistributionPoint | Format-List *
Get-CAAuthorityInformationAccess | Format-List *
certutil.exe -getreg CA\CRLPeriod
certutil.exe -getreg CA\CRLOverlapPeriod
certutil.exe -verify -urlfetch '.\issued.cer' Back up keys, database, configuration, and procedures
A recoverable CA needs its signing private key and certificate, CA database and logs, registry configuration, CAPolicy.inf, issued templates and ACL documentation, HSM configuration, CRL/AIA publication content, passwords or quorum procedures, and tested restore instructions. Backup-CARoleService can protect exported keys with SecureString input. Store backups encrypted, offline, access-controlled, and separated from ordinary server backups. Restore-CARoleService is destructive and must be rehearsed in an isolated recovery environment using matching CA identity and provider prerequisites.
$BackupPath = 'E:\CA-Backup'
$BackupPassword = Read-Host 'CA backup password' -AsSecureString
try {
# Approved elevated backup window only:
# Backup-CARoleService -Path $BackupPath -Password $BackupPassword
Get-ChildItem -LiteralPath $BackupPath -ErrorAction SilentlyContinue
}
finally { $BackupPassword.Dispose() } Harden the CA as a dedicated trust service
Limit interactive logon, installed software, network paths, CA manager permissions, template management, backup access, and HSM administration. Enable CA auditing together with Windows object-access audit policy, protect event forwarding, and alert on configuration changes, issuance spikes, failed requests, service stops, expiring CA certificates, and CRL publication failures. Keep root CAs offline except for controlled ceremonies. Patch and restart through a documented ceremony that first confirms fresh CRLs, backups, and subordinate availability.
auditpol.exe /get /subcategory:'Certification Services'
certutil.exe -getreg CA\AuditFilter
Get-WinEvent -FilterHashtable @{ LogName='Application'; ProviderName='Microsoft-Windows-CertificationAuthority' } `
-MaxEvents 100 | Select-Object TimeCreated, Id, LevelDisplayName, Message Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- Microsoft LearnActive Directory Certificate Services documentationlearn.microsoft.com
- Microsoft LearnWhat is Active Directory Certificate Services?learn.microsoft.com
- Microsoft LearnPKI design considerationslearn.microsoft.com
- Microsoft LearnADCSDeployment modulelearn.microsoft.com
- Microsoft LearnADCSAdministration modulelearn.microsoft.com
- Microsoft LearnCA backup and restore PowerShell cmdletslearn.microsoft.com
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



