Public Key Infrastructure (PKI) deployment: AD CS provides the server roles needed to stand up an enterprise PKI, establishing the trust hierarchy, certificate policies, and infrastructure that lets an organization issue and manage its own digital certificates for authentication, encryption, and signing.
02
Certificate Authority (CA) - Root and Subordinate/Enterprise: AD CS can operate as a standalone or Active Directory-integrated (enterprise) CA, configured as an offline root CA at the top of the trust chain or as issuing subordinate CAs beneath it, allowing a tiered architecture that isolates and protects the root key.
03
Digital certificate issuance and management: The CA receives certificate requests, validates them against policy, signs and issues X.509 certificates, and tracks their full lifecycle in the CA database, providing a central record of every certificate issued, pending, revoked, or failed.
04
Certificate enrollment (manual, auto-enrollment): Certificates can be requested manually through the Certificates MMC, web enrollment, or command-line tools, or distributed automatically via Group Policy auto-enrollment so domain users and computers silently receive and renew the certificates appropriate to their role.
05
Certificate templates management: Enterprise CAs use templates that predefine a certificate's purpose, key length, validity period, allowed subjects, cryptographic settings, and enrollment permissions. Administrators clone and customize templates to control exactly which principals can obtain which kinds of certificates.
Your plan caps how many capabilities are shown — upgrade to see the full list