The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Inspect AD CS featuresGet-WindowsFeature AD-Certificate,ADCS-Cert-AuthorityView examples
Inspect domain contextGet-CimInstance Win32_ComputerSystem | Select-Object Name,Domain,PartOfDomainView examples
Install CA binariesInstall-WindowsFeature ADCS-Cert-Authority ` -IncludeManagementTools -WhatIfView examples
Configure an enterprise subordinate CAInstall-AdcsCertificationAuthority -CAType ` EnterpriseSubordinateCA -CACommonName ` 'Contoso Issuing CA 01' -WhatIfView examples
Inspect CA serviceGet-Service CertSvcView examples
Read CA configurationcertutil.exe -getreg CAView examples
List issued templatesGet-CATemplateView examples
Publish a templateAdd-CATemplate -Name 'ContosoWebServer' -WhatIfView examples
Inspect pending requestscertutil.exe -view -restrict 'Disposition=9' -out ` 'RequestID,RequesterName,CommonName'View examples
Inspect issued requestscertutil.exe -view -restrict 'Disposition=20' -out ` 'RequestID,CommonName,NotAfter'View examples
Revoke a certificatecertutil.exe -revoke $Serial KeyCompromiseView examples
Publish a new CRLcertutil.exe -crlView examples
Verify certificate URLscertutil.exe -url '.\issued.cer'View examples
Back up CA database and keyBackup-CARoleService -Path 'E:\CA-Backup' -Password ` (Read-Host -AsSecureString)View examples
Export CA configurationreg.exe export ` 'HKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration' ` '.\ca-config.reg' /yView examples
Read CA operational eventsGet-WinEvent -LogName 'Application' -ProviderName ` 'Microsoft-Windows-CertificationAuthority' -MaxEvents ` 100View examples

Active Directory Certificate Services is a long-lived trust system, not merely a server role. CA hierarchy, name, key protection, algorithms, validity, templates, issuance policy, revocation publishing, auditing, backup, and disaster recovery must be designed before installation. Most deployment actions are irreversible or disruptive without a migration, so examples emphasize inspection, staged plans, protected keys, and recovery drills rather than one-line production installation.

Step by step

Detailed examples

01

Design the PKI before installing the CA

Choose an offline standalone root and online enterprise issuing tier when organizational risk warrants it. Decide CA names, validity periods, algorithms, key sizes, HSM or KSP, database and log locations, AIA/CDP URLs, template governance, auditing, backup custody, and renewal strategy first; the CA name cannot simply be renamed later. Enterprise CAs require AD DS membership and permissions, while standalone CAs do not use templates. Verify supported Windows Server edition and role prerequisites, accurate time, DNS, and protected administrative access.

Collect non-destructive host prerequisites
Get-ComputerInfo -Property WindowsProductName,WindowsVersion,OsBuildNumber
Get-CimInstance Win32_ComputerSystem | Select-Object Name, Domain, PartOfDomain
Get-WindowsFeature AD-Certificate, ADCS-Cert-Authority
Get-Tpm -ErrorAction SilentlyContinue | Select-Object TpmPresent, TpmReady
Back to quick reference ↑
02

Separate role installation from CA configuration

Installing ADCS-Cert-Authority adds binaries; Install-AdcsCertificationAuthority creates or joins the trust hierarchy. Run from an elevated Windows PowerShell session on a supported Windows Server. Enterprise CA deployment requires appropriate AD privileges and forest readiness. Review CAPolicy.inf before installation when defaults must change. WhatIf is useful but cannot model HSM prompts, AD publication, service startup, or every provider effect. Some role changes may request a restart; CA configuration starts CertSvc and creates sensitive keys and database state.

Preview a subordinate CA deployment
$Plan = @{
    CAType = 'EnterpriseSubordinateCA'
    CACommonName = 'Contoso Issuing CA 01'
    CryptoProviderName = 'RSA#Microsoft Software Key Storage Provider'
    HashAlgorithmName = 'SHA256'
    KeyLength = 3072
}
Install-WindowsFeature ADCS-Cert-Authority -IncludeManagementTools -WhatIf
Install-AdcsCertificationAuthority @Plan -WhatIf
Back to quick reference ↑
03

Inspect local CA identity and service health

The ADCSAdministration module operates primarily on the local CA. Confirm which CA and registry path a session targets before acting. CertSvc restart interrupts enrollment and can delay publication, so schedule configuration changes. certutil is powerful and includes mutating verbs; pair exact documented switches with change approval. Monitor database space, log volume, service state, enrollment latency, CA certificate expiration, signing key health, and failed publication—not just whether the service is running.

Build a read-only CA health snapshot
Get-Service CertSvc | Select-Object Status, StartType, Name
certutil.exe -getreg CA
certutil.exe -getreg CA\CRLPublicationURLs
Get-ChildItem Cert:\LocalMachine\My |
    Where-Object HasPrivateKey | Select-Object Subject, Thumbprint, NotAfter
Back to quick reference ↑
04

Govern templates in Active Directory and on the CA

Enterprise certificate templates are AD objects with version, cryptography, subject construction, application policies, validity, renewal, issuance requirements, and ACLs. Add-CATemplate only publishes an existing template on the CA; it does not safely design the template. Avoid enrollee-supplied subject or broad enrollment rights unless the complete authentication threat model supports them. Separate template managers, CA managers, and enrollment principals. Changes replicate through AD and can immediately affect autoenrollment at scale.

Review CA-published templates before a change
Get-CATemplate | Sort-Object Name | Format-Table Name
# Validate the AD template ACL, EKUs, subject rules, key export, and issuance policy separately.
# Approved CA change only:
# Add-CATemplate -Name 'ContosoWebServer' -WhatIf
Back to quick reference ↑
05

Verify certificate identity before approval or revocation

Pending approval is a security decision: validate requester identity, template, subject alternative names, intended usage, ownership, and policy evidence. Revocation is disruptive and does not erase a certificate; relying parties must receive a fresh CRL or OCSP response. Choose the truthful reason code, record the incident, and verify the exact serial or request ID. The built-in ADCSAdministration module does not expose CA database approval or revocation cmdlets; use the documented certutil verbs or the Certification Authority console. certutil has no WhatIf.

Inspect CA database rows without changing disposition
certutil.exe -view -restrict 'Disposition=9' `
    -out 'RequestID,RequesterName,CommonName,CertificateTemplate,Request.SubmittedWhen'
certutil.exe -view -restrict 'Disposition=20' `
    -out 'RequestID,RequesterName,CommonName,SerialNumber,NotAfter'
# certutil -resubmit, -deny, and -revoke mutate CA state; require independent review.
Back to quick reference ↑
06

Make revocation information continuously reachable

CRL distribution points and Authority Information Access paths are embedded into issued certificates, so a bad URL persists for their lifetime. Publish base and delta CRLs early enough to survive outages and monitor HTTP/LDAP retrieval from every relying network. certutil -crl publishes signed revocation data immediately and has no dry run; verify Next Update and replicate output to all configured distribution points. certutil -url provides an interactive retrieval check, while certutil -verify -urlfetch validates a chain using network retrieval.

Inspect publication settings and a sample certificate
Get-CACrlDistributionPoint | Format-List *
Get-CAAuthorityInformationAccess | Format-List *
certutil.exe -getreg CA\CRLPeriod
certutil.exe -getreg CA\CRLOverlapPeriod
certutil.exe -verify -urlfetch '.\issued.cer'
Back to quick reference ↑
07

Back up keys, database, configuration, and procedures

A recoverable CA needs its signing private key and certificate, CA database and logs, registry configuration, CAPolicy.inf, issued templates and ACL documentation, HSM configuration, CRL/AIA publication content, passwords or quorum procedures, and tested restore instructions. Backup-CARoleService can protect exported keys with SecureString input. Store backups encrypted, offline, access-controlled, and separated from ordinary server backups. Restore-CARoleService is destructive and must be rehearsed in an isolated recovery environment using matching CA identity and provider prerequisites.

Prepare a full backup with an interactive password
$BackupPath = 'E:\CA-Backup'
$BackupPassword = Read-Host 'CA backup password' -AsSecureString
try {
    # Approved elevated backup window only:
    # Backup-CARoleService -Path $BackupPath -Password $BackupPassword
    Get-ChildItem -LiteralPath $BackupPath -ErrorAction SilentlyContinue
}
finally { $BackupPassword.Dispose() }
Back to quick reference ↑
08

Harden the CA as a dedicated trust service

Limit interactive logon, installed software, network paths, CA manager permissions, template management, backup access, and HSM administration. Enable CA auditing together with Windows object-access audit policy, protect event forwarding, and alert on configuration changes, issuance spikes, failed requests, service stops, expiring CA certificates, and CRL publication failures. Keep root CAs offline except for controlled ceremonies. Patch and restart through a documented ceremony that first confirms fresh CRLs, backups, and subordinate availability.

Collect audit posture and recent events
auditpol.exe /get /subcategory:'Certification Services'
certutil.exe -getreg CA\AuditFilter
Get-WinEvent -FilterHashtable @{ LogName='Application'; ProviderName='Microsoft-Windows-CertificationAuthority' } `
    -MaxEvents 100 | Select-Object TimeCreated, Id, LevelDisplayName, Message
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Microsoft LearnActive Directory Certificate Services documentationlearn.microsoft.com
  2. Microsoft LearnWhat is Active Directory Certificate Services?learn.microsoft.com
  3. Microsoft LearnPKI design considerationslearn.microsoft.com
  4. Microsoft LearnADCSDeployment modulelearn.microsoft.com
  5. Microsoft LearnADCSAdministration modulelearn.microsoft.com
  6. Microsoft LearnCA backup and restore PowerShell cmdletslearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback