Skip to main content
Version: 2.3.0

AD-CFG-15 - Enrollment CA certificate details should be retrievable

Overview​

Enrollment-capable CA certificates include validity periods and other critical properties. Expired or invalid CA certificates can break certificate issuance and domain authentication flows. In addition, unexpected certificate replacements (e.g., unknown thumbprints) can indicate PKI tampering.

Control Type​

Operational

Security Recommendation​

  • Monitor CA certificate expiration and rotate certificates through an approved operational process.
  • Validate certificate thumbprints/subjects/issuers against your known-good CA configuration.
  • Alert when CA certificates are within your rotation window (commonly 30/60 days, depending on your policy).
  • Ensure CRL/OCSP and publication settings remain correct after certificate updates.

How the Test Works​

  • Enumerates enrollment-capable CA objects in Active Directory.
  • Retrieves CA certificate details associated with those enrollment services.
  • Evaluates certificate validity (e.g., already expired, or expiring soon based on your configured thresholds) and highlights unexpected certificate identity details.

Test Metadata​

FieldValue
Test IDAD-CFG-15
SeverityInfo
SuiteActive Directory
CategoryAD.Config
PowerShell testTest-MtAdEnrollmentCaCertificateDetails
TagsAD, AD-CFG-15, AD.Config

Source​

  • Pester test: tests/ad/config/Test-MtAdEnrollmentCaCertificateDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/config/Test-MtAdEnrollmentCaCertificateDetails.ps1