Configure Active Directory Certificate Services - NDES
You must install AD CS - Network Device Enrollment Service on a server separate from your Enterprise CA.
Go to Start > Administrative Tools > Server Manager > Manage. Then, select [ Add roles and features ].
On the Before You Begin window, select [ Next ].
Choose the installation type: Role-based or feature-based installation. Select [ Next ].
On the Server Selection page, select the server from the domain (or local machine) on which to install AD CS. Select [ Next ].
On the Server Roles page, check the box next to Active Directory Certificate Services. Select [ Next ] and then select [ Add Features ].
On the Features page, select the following options and then select [ Next ].
- Select .NET Framework 3.5 Features and include HTTP Activation
- Select .NET Framework 4.8 Features and include HTTP Activation under WCF Services
On the AD CS page, select [ Next ].
On the Role Services page, select Network Device Enrollment Service . Select [ Next ].
On the Web Server Role (IIS) page, select [ Next ].
On the Role Services page, select the following:
- Security
- Request Filtering
- Application development
- Net Extensibility 4.8
- ASP.NET 4.8
- Management Tools
- IIS Management Tools
- IIS 6 Management Compatibility
- IIS 6 Metabase Compatibility
- IIS 6 WMI Compatibility
Select [ Next ] and then [ Install ].
After the installation completes, select [ Close ].
Before moving on to configuring AD CS NDES, you must first set the permissions for your Service Account and Application Pool account.
On the NDES server, use the windows search bar and look for Local Users and Groups. Open it.
In the left toolbar, select [ Groups ].
Locate the IIS_ISURS group and right-click it. Select [ Properties ].
Select [ Add ] and add both your Service Account and your NDES Application Pool account.
Select [ Apply ] and then [ OK ].
The Domain Administrator account you plan to use for NDES as the Service Account must have Logon as a Service enabled. To enable it:
On the NDES server, use the windows search bar and look for Local Security Policy. Open it.
Expand Local Policies and select [ User Rights Assignment ].
Locate and double-click [ Log on as a service ].
Select [ Add user or Group ].
Add your Domain Administrator account acting as the NDES Service Account. Select [ OK ].
For more information on installing and configuring Active Directory Certificate Services - NDES, refer to the Microsoft documentation.