AD-CFG-15 - Enrollment CA certificate details should be retrievable
Overviewโ
Enrollment-capable CA certificates include validity periods and other critical properties. Expired or invalid CA certificates can break certificate issuance and domain authentication flows. In addition, unexpected certificate replacements (e.g., unknown thumbprints) can indicate PKI tampering.
Security Recommendationโ
- Monitor CA certificate expiration and rotate certificates through an approved operational process.
- Validate certificate thumbprints/subjects/issuers against your known-good CA configuration.
- Alert when CA certificates are within your rotation window (commonly 30/60 days, depending on your policy).
- Ensure CRL/OCSP and publication settings remain correct after certificate updates.
How the Test Worksโ
- Enumerates enrollment-capable CA objects in Active Directory.
- Retrieves CA certificate details associated with those enrollment services.
- Evaluates certificate validity (e.g., already expired, or expiring soon based on your configured thresholds) and highlights unexpected certificate identity details.
Related Testsโ
- Test-MtAdEnterpriseCaCount: Helps confirm which CAs are expected to exist.
- Test-MtAdTrustedRootCaCount: Validates the trust anchors that support issued certificates.
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-CFG-15 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Config |
| PowerShell test | Test-MtAdEnrollmentCaCertificateDetails |
| Tags | AD, AD-CFG-15, AD.Config |
Sourceโ
- Pester test:
tests/ad/config/Test-MtAdEnrollmentCaCertificateDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/config/Test-MtAdEnrollmentCaCertificateDetails.ps1

