Installing the default set of certificate templates
If not installed, install the default set of Microsoft certificate templates, as described in the following sections.
- Enabling the Certificate Templates snap-in
- Installing the default set of Microsoft Certificate Templates using the snap-in
ℹ This section is mainly for new Microsoft Active Directory forest deployments, as they do not include a set of Microsoft certificate templates.
Enabling the Certificate Templates snap-in
You can enable the Certificate Templates snap-in by simply running the following PowerShell command.
Install-WindowsFeature RSAT-ADCS-mgmt
For example:

Alternatively, you can enable the Certificate Templates snap-in using the Windows Server Manager wizard.
To enable the Certificate Templates snap-in with the Windows Server Manager:
-
Open the Windows Server Manager – for example, by pressing the Windows key on the keyboard and typing “Server Manager” in the search box.

-
On the top-right of the window, click Manage > Add Roles and Features.
-
In the Select Features dialog, click Next until the Features section is displayed.

-
Check the following box: Remote Server Administration Tools / Remote Administration Tools / Active Directory Certificate Services Tools.
-
Click Next until the Install button appears, and click the Install button.
-
Wait while the installation is complete before proceeding to the next step.
Installing the default set of Microsoft Certificate Templates using the snap-in
After Enabling the Certificate Templates snap-in, add the snap-in to install the default set of Microsoft Certificate Templates.
To install the default set of Microsoft Certificate Templates using the snap-in:
-
Log in to the root Active Directory Domain of the Windows forest as a member of both the Enterprise Admins and Domain Admin groups.
⚠ Users without these privileges cannot access the dialog options described in this section.
-
Open Microsoft Management Console (MMC) – for example, by pressing the Windows key on the keyboard and typing “MMC.” (ending with a period) in the search box.

-
Select File > Add/Remove Snap-in.
-
In the Available snap-ins column, select Certificate Templates.

-
Click Add to move the Certificate Templates snap-in to the Selected snap-ins column.
-
Click OK to close the Add or Remove Snap-ins wizard and return to the Microsoft Management Console.
-
In the Microsoft Management Console, click Certificate Templates under Console Root.

-
Click Yes in the confirmation dialog.

⚠ If you accidentally click No in the confirmation dialog, remove the Active Directory Certificate Services Tools and repeat all the steps explained in Installing the default set of Microsoft Certificate Templates.