Entrust PKI as a Service

Installing the default set of certificate templates

If not installed, install the default set of Microsoft certificate templates, as described in the following sections.


ℹ This section is mainly for new Microsoft Active Directory forest deployments, as they do not include a set of Microsoft certificate templates.


Enabling the Certificate Templates snap-in

You can enable the Certificate Templates snap-in by simply running the following PowerShell command.

Install-WindowsFeature RSAT-ADCS-mgmt

For example:

PNG

Alternatively, you can enable the Certificate Templates snap-in using the Windows Server Manager wizard.

To enable the Certificate Templates snap-in with the Windows Server Manager:

  1. Open the Windows Server Manager – for example, by pressing the Windows key on the keyboard and typing “Server Manager” in the search box.

    PNG

  2. On the top-right of the window, click Manage > Add Roles and Features.

  3. In the Select Features dialog, click Next until the Features section is displayed.

    PNG

  4. Check the following box: Remote Server Administration Tools / Remote Administration Tools / Active Directory Certificate Services Tools.

  5. Click Next until the Install button appears, and click the Install button.

  6. Wait while the installation is complete before proceeding to the next step.

Installing the default set of Microsoft Certificate Templates using the snap-in

After Enabling the Certificate Templates snap-in, add the snap-in to install the default set of Microsoft Certificate Templates.

To install the default set of Microsoft Certificate Templates using the snap-in:

  1. Log in to the root Active Directory Domain of the Windows forest as a member of both the Enterprise Admins and Domain Admin groups.


    ⚠ Users without these privileges cannot access the dialog options described in this section.


  2. Open Microsoft Management Console (MMC) – for example, by pressing the Windows key on the keyboard and typing “MMC.” (ending with a period) in the search box.

    PNG

  3. Select File > Add/Remove Snap-in.

  4. In the Available snap-ins column, select Certificate Templates.

    PNG

  5. Click Add to move the Certificate Templates snap-in to the Selected snap-ins column.

  6. Click OK to close the Add or Remove Snap-ins wizard and return to the Microsoft Management Console.

  7. In the Microsoft Management Console, click Certificate Templates under Console Root.

    PNG

  8. Click Yes in the confirmation dialog.

    PNG


    ⚠ If you accidentally click No in the confirmation dialog, remove the Active Directory Certificate Services Tools and repeat all the steps explained in Installing the default set of Microsoft Certificate Templates.