Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Active Directory: Deploying and managing Certificate Service
Rating: 4.3 out of 5(234 ratings)
9,644 students

Active Directory: Deploying and managing Certificate Service

Deploying and managing Certificates (ADCS)
Created byVitalii Shumylo
Last updated 9/2026
English
English [Auto],

What you'll learn

  • Deploy CAs
  • Administer CAs
  • Troubleshoot and maintain CAs
  • Getting know with CA technology

Course content

3 sections • 23 lectures • 2h 31m total length
  • Building Windows Server 2025 AD Domain from Hyper-V Lab9:34

    Promote W25 lead Dc1 to a domain controller and build a complete active directory domain with dns in a Hyper-V lab, using forest functional level 2025 and essence.com zones.

  • Integrating Server Core via PowerShell Domain Setup5:48

    Learn how to integrate a Windows Server Core into an Active Directory domain using PowerShell, validate DNS, enable remote management, and install DNS remotely.

  • Configuring Domain Members and RSAT Tools Integration8:06

    Join member servers to the domain and verify DNS settings to enable seamless domain resource access, then enable remote management and install RSAT tools for Active Directory administration.

  • Deploying Windows Admin Center for Server Management3:51

    Install Windows Admin Center on the SVR one member server with express setup and a self-signed certificate. Log in with domain credentials and add DC1 and core1 for centralized management.

  • Creating AD Lab Users, Groups, and Remote Access Configuration7:50

    Demonstrates creating AD lab users and groups, establishing organizational units, and enabling remote desktop for Windows 11 clients by adding the lab group to Remote Desktop Users.

  • IIS Web Server Installation and Configuration for PKI6:06

    Configure a dedicated IIS web server for PKI certificate distribution, create and secure the cert enrollment directory, publish CRLs and certificates, and set permissions for the CERT publishers group.

  • PKI Share Permissions and Virtual Directory Setup2:58

    Configure share and NTFS permissions for the certain role folder with modify access for the Publishers group, then create a virtual directory in IIS to expose certificates and CRLs.

  • Directory Browsing and Delta CRL Configuration in IIS7:49

    Enable directory browsing to support troubleshooting and manual retrieval of certificates and CRLs. Enable double escaping for delta CRLs in IAS to allow plus-sign file names for efficient validation.

  • Offline Root CA Environment Preparation and Security6:32

    Deploys a secure offline root CA as the trust anchor for a PKI hierarchy, with air-gap isolation, security hardening, auditing, and proper authority information access and CRL distribution points.

  • CA Policy File Configuration and Security Parameters7:27

    Create and configure the ca-policy.inf file on the root CA to define security and policy settings, certificate extensions, and parameters such as 4096-bit keys and 20-year validity.

  • Root Certificate Authority Installation and Setup4:25

    Install the core certificate services, configure a standalone root CA with a new private key (4096-bit, 256 hash) and 20-year validity, following CDP guidelines avoiding delta CRLs.

  • Root CA CDP Configuration and Local Filesystem Setup9:36

    optimize root ca settings by removing default CDP entries and configuring two custom CDP entries: a local file system entry for CRL generation and an HTTP distribution entry for offline root CA.

  • Authority Information Access Configuration for Root CA3:39

    Configure authority information access for the root CA by adding a custom AA entry that directs clients to download the root certificate from the web server for chain building.

  • PKI File Transfer Using Air-Gapped Security Methods2:52

    Use air-gapped security to move PKI files, bringing an external drive online and copying the root certificate and CRL from the system32 sort SVR folder, then power off.

  • Enterprise CA Policy Configuration and Prerequisites4:14

    Deploy an enterprise issuing CA with Active Directory Certificate Services on Windows Server 2025. Create a CA policy INF to enforce 1496-bit renewal keys, ten-year renewals, and zero default templates.

  • Root CA Certificate and CRL Publishing Methods6:58

    Publish the root CA certificate and CRL to Active Directory, the PKI web server, and local stores to establish trusted distribution points for domain-joined and non-domain devices.

  • Enterprise CA Installation and Certificate Request Process5:52

    Install and configure enterprise certificate services, add the Certificate Authority and Web Enrollment roles, enable dependencies, and generate a certificate request for a subordinate CA signed by the root CA.

  • Root CA Certificate Request Processing and Signing5:55

    Transfer certificate requests securely to the offline root ca via removable media in a two-tier pki setup, then sign and retrieve the issued certificate.

  • Enterprise CA Certificate Installation and Final Setup7:24

    Install and activate the enterprise certificate authority, then configure CRL and AIA/CDP extensions to support certificate issuance and chain validation.

Requirements

  • Familiarity with general Windows and Microsoft server administration and technologies

Description

The public key infrastructure (PKI) consists of several components, such as certification authority (CA), that help you secure organizational communications and transactions. You can use CAs to manage, distribute, and validate the digital certificates that you use to secure information. You can install Active Directory Certificate Services (AD CS) as a root CA or a subordinate CA in your organization. In this module, you will learn about deploying and managing CAs.


Objectives

After completing this course, you will be able to:

· Deploy CAs.

· Administer CAs.

· Troubleshoot and maintain CAs.

Who this course is for:

  • Active Directory Administrators
  • Windows Server Administrators