Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Active Directory: Deploying and managing Certificate Service
Rating: 4.2 out of 5(232 ratings)
9,644 students

Active Directory: Deploying and managing Certificate Service

Deploying and managing Certificates (ADCS)
Created byVitalii Shumylo
Last updated 10/2025
English
English [Auto],

What you'll learn

  • Deploy CAs
  • Administer CAs
  • Troubleshoot and maintain CAs
  • Getting know with CA technology

Course content

3 sections22 lectures2h 30m total length
  • Building Windows Server 2025 AD Domain from Hyper-V Lab9:30

    Promote W25 lead Dc1 to a domain controller and build a complete active directory domain with dns in a Hyper-V lab, using forest functional level 2025 and essence.com zones.

  • Integrating Server Core via PowerShell Domain Setup5:48

    Learn how to join a core server to a domain using PowerShell, verify DNS and network settings, restart, and install DNS service remotely from the domain controller.

  • Configuring Domain Members and RSAT Tools Integration8:06

    Join member servers to the domain and verify DNS settings to enable seamless domain resource access, then enable remote management and install RSAT tools for Active Directory administration.

  • Deploying Windows Admin Center for Server Management3:51

    Install Windows Admin Center on the SVR one member server with express setup and a self-signed certificate. Log in with domain credentials and add DC1 and core1 for centralized management.

  • Creating AD Lab Users, Groups, and Remote Access Configuration7:49

    Demonstrates creating AD lab users and groups, establishing organizational units, and enabling remote desktop for Windows 11 clients by adding the lab group to Remote Desktop Users.

  • IIS Web Server Installation and Configuration for PKI6:06

    Configure a dedicated IIS web server for PKI certificate distribution, create and secure the cert enrollment directory, publish CRLs and certificates, and set permissions for the CERT publishers group.

  • PKI Share Permissions and Virtual Directory Setup2:57

    Configure share and NTFS permissions for the certain role folder with modify access for the Publishers group, then create a virtual directory in IIS to expose certificates and CRLs.

  • Directory Browsing and Delta CRL Configuration in IIS7:49

    Enable directory browsing for PKI troubleshooting and certificate distribution in IIS. Enable delta CRL distribution by configuring double escaping and test with a DNS alias.

  • Offline Root CA Environment Preparation and Security6:32

    Deploys a secure offline root CA as the trust anchor for a PKI hierarchy, with air-gap isolation, security hardening, auditing, and proper authority information access and CRL distribution points.

  • CA Policy File Configuration and Security Parameters7:27

    Define and configure a CA policy file before installing, embedding policy, OID, and notice text; set cert service server parameters, renewal settings, and key usage for server and client authentication.

  • Root Certificate Authority Installation and Setup4:25

    Install the core certificate services, configure a standalone root CA with a new private key (4096-bit, 256 hash) and 20-year validity, following CDP guidelines avoiding delta CRLs.

  • Root CA CDP Configuration and Local Filesystem Setup9:36

    optimize root ca settings by removing default CDP entries and configuring two custom CDP entries: a local file system entry for CRL generation and an HTTP distribution entry for offline root CA.

  • Authority Information Access Configuration for Root CA3:39

    Configure authority information access for the root CA by adding a custom AA entry that directs clients to download the root certificate from the web server for chain building.

  • PKI File Transfer Using Air-Gapped Security Methods2:51

    Use air-gapped security to move PKI files, bringing an external drive online and copying the root certificate and CRL from the system32 sort SVR folder, then power off.

  • Enterprise CA Policy Configuration and Prerequisites4:14

    Deploy an enterprise issuing CA with Active Directory Certificate Services on Windows Server 2025. Create a CA policy INF to enforce 1496-bit renewal keys, ten-year renewals, and zero default templates.

  • Root CA Certificate and CRL Publishing Methods6:58

    Publish your root CA certificate and CRL to Active Directory, the PKI web server, and the local certificate store to establish a trusted PKI infrastructure for clients.

  • Enterprise CA Installation and Certificate Request Process5:52

    Install and configure enterprise certificate services, add the Certificate Authority and Web Enrollment roles, enable dependencies, and generate a certificate request for a subordinate CA signed by the root CA.

  • Root CA Certificate Request Processing and Signing5:55

    Transfer certificate requests securely to the offline root ca via removable media in a two-tier pki setup, then sign and retrieve the issued certificate.

  • Enterprise CA Certificate Installation and Final Setup7:24

    Install and activate the enterprise certificate authority, then configure CRL and AIA/CDP extensions to support certificate issuance and chain validation.

Requirements

  • Familiarity with general Windows and Microsoft server administration and technologies

Description

The public key infrastructure (PKI) consists of several components, such as certification authority (CA), that help you secure organizational communications and transactions. You can use CAs to manage, distribute, and validate the digital certificates that you use to secure information. You can install Active Directory Certificate Services (AD CS) as a root CA or a subordinate CA in your organization. In this module, you will learn about deploying and managing CAs.


Objectives

After completing this course, you will be able to:

· Deploy CAs.

· Administer CAs.

· Troubleshoot and maintain CAs.

Who this course is for:

  • Active Directory Administrators
  • Windows Server Administrators