You have one domain administrator account acting as a Service Account and must create an NDES user acting as the Application Pool account.
Create the user
Perform the following steps to create the NDES Application Pool user and assign it to IIS_IUSRS:Create the certificate template
Perform the following steps to create the NDES certificate template:On the left toolbar, expand your domain and right-click Certificate Templates. Then, select [ Manage ].
In Extensions, select Application Policies > Edit and add both Client Authentication and Server Authentication.
In Security, select [ Add ] and perform the following steps:
- In the Enter the object names to select box, enter the name of your NDES Application Pool user and select** [ OK ]**.
- Give your NDES Application Pool user the Read and Enroll permissions for the certificate.
- Give your NDES Service Account Full Control.
In Request Handling, set the purpose to Signature and Encryption. Select the options Include symmetric algorithms allowed by the subject and Allow private keys to be exported.
Deploy the certificate
Perform the following steps to deploy the NDES certificate:Expand your domain on the left toolbar and right-click Certificate Templates. Then, select New > Certificate Template to issue.
For more information on installing and configuring Active Directory Certificate Services - NDES, refer to the Microsoftdocumentation.

