icon icon

PKI in the Microsoft Environment – Implementation and Management of AD CS in Windows Server 2022/2025

icon

Training process

Training needs analysis

If you have specific requirements regarding the training programme, we will carry out a training needs analysis for you. This will guide us on which aspects of the programme should receive greater emphasis, so that the training programme meets your specific needs.

What will you gain?

icon

Design the right PKI architecture - You will learn how to choose a single-tier or multi-tier model, separate Root CA and Issuing CA roles, and plan a trusted certificate infrastructure that fits your organization.

icon

Deploy AD CS on your own - You will go through AD CS installation and configuration on Windows Server 2022/2025, so you can launch your first CA, choose the proper CA type, and set critical parameters.

icon

Build a secure CA hierarchy - You will learn how to implement an offline Root CA and Issuing CA, correctly sign subordinate CA certificates, and publish them so the full hierarchy stays secure and reliable.

icon

Configure CRL, CDP, AIA and OCSP - You will learn to publish CRLs and Delta CRLs, configure CDP and AIA locations, and deploy Online Responder so systems can validate certificate status quickly and correctly.

icon

Create practical certificate templates - You will master creating and modifying certificate templates, setting permissions, extensions, and autoenrollment, so you can issue certificates to users, servers, and devices.

icon

Implement Smart Card authentication - You will see how to prepare the environment for smart card logon, configure the right templates, and integrate user certificates with Active Directory and Kerberos.

icon

Manage the certificate lifecycle - You will learn how to monitor CA operations, revoke certificates, review logs, automate tasks with PowerShell, and keep your PKI environment under control in daily administration.

icon

Prepare CA recovery and backup - You will learn key archival, KRA configuration, backup of the CA database and private keys, and full CA recovery procedures after a failure, incident, or incorrect change.

Training programme

1. Introduction to PKI and Microsoft Certificate Services

  • basics of cryptography and PKI:
    • symmetric and asymmetric cryptography,
    • public and private key,
    • hash functions and digital signature,
    • digital certificates – certificate structure and fields,
  • PKI standards and architecture:
    • X.509 standard,
    • certification chain (certificate chain),
    • trust model and root of trust,
    • role of certification authorities (CA),
  • Active Directory Certificate Services:
    • AD CS components,
    • AD CS roles and services,
    • PKI usage scenarios in the Microsoft environment.

2. PKI Architecture in an Organizational Environment

  • PKI infrastructure design:
    • PKI topologies,
    • single-tier vs multi-tier PKI,
    • root CA and issuing CA model,
  • certificate infrastructure planning:
    • certificate policy (CP),
    • certification practice statement (CPS),
    • planning names, keys and algorithms,
  • security requirements:
    • protection of private keys,
    • HSM (Hardware Security Module),
    • separation of administrative roles.

3. Installation and configuration of AD CS

  • installation of the Active Directory Certificate Services role:
    • environment preparation,
    • system requirements,
    • configuration of the first CA,
  • types of certification authorities:
    • Enterprise CA,
    • Standalone CA,
    • Root CA,
    • Subordinate CA,
  • basic CA configuration:
    • certificate database configuration,
    • configuration of keys and algorithms,
    • configuration of certificate validity periods.

4. Implementation of AD CS in a multi-tier CA structure

  • design of the CA hierarchy:
    • offline Root CA,
    • Issuing CA,
    • security models,
  • installation of the Root CA:
    • configuration of the offline Root CA,
    • generation of the parent certificate,
  • installation of the Issuing CA:
    • certificate request from the Root CA,
    • signing the CA certificate,
    • publication of the certificate,
  • integration of the CA with Active Directory:
    • publication of certificates in AD,
    • autoenrollment,
    • management of certificate policy.

5. CRL Points and Certificate Revocation Mechanisms

  • CRL lists:
    • CRL operation mechanism,
    • CRL publication,
    • distribution points configuration,
  • Delta CRL:
    • differences between CRL and Delta CRL,
    • list refresh configuration,
  • CDP and AIA points:
    • CDP configuration (CRL Distribution Points),
    • AIA configuration (Authority Information Access).

6. OCSP – Online Certificate Status Protocol

  • the role of OCSP in the PKI infrastructure:
    • OCSP operation mechanism,
    • advantages of OCSP over CRL,
  • installation of the Online Responder service:
    • role configuration,
    • integration with the CA,
  • configuration of responders:
    • configuration of OCSP response signing,
    • high availability of OCSP.

7. Certificate Templates (Certificate Templates)

  • template architecture:
    • template versions,
    • certificate extensions,
  • creation and configuration of templates:
    • modification of existing templates,
    • creation of new templates,
  • certificate distribution:
    • manual certificate requests,
    • autoenrollment,
    • certificate lifecycle management.

8. Authentication using Smart Card (MFA)

  • introduction to certificate-based authentication:
    • user certificates,
    • Kerberos authentication with a certificate,
  • Smart Card Logon configuration:
    • infrastructure requirements,
    • certificate template configuration,
  • MFA implementation using smart cards:
    • card reader configuration,
    • issuing user certificates,
    • integration with Active Directory.

9. PKI Management and Administration

  • CA administration:
    • management of issued certificates,
    • revocation of certificates,
    • monitoring of the CA,
  • auditing and logging:
    • audit of PKI events,
    • analysis of security logs,
  • automation of certificate management:
    • PowerShell for AD CS,
    • automatic renewal of certificates.

10. Key Recovery and CA Backups

  • key archival:
    • Key Archival,
    • Key Recovery Agent (KRA) configuration,
  • certificate recovery:
    • private key recovery process,
    • security procedures,
  • CA backup and restore:
    • certificate database backup,
    • private key backup,
    • disaster recovery for CA.

11. PKI Infrastructure Security

  • best practices:
    • securing the Root CA,
    • protection of private keys,
  • CA hardening:
    • network segmentation,
    • security policies,
  • common errors in PKI implementation:
    • problems with CRL,
    • incorrect configuration of templates,
    • incorrect CA architecture.

12. Practical workshops

  • building PKI infrastructure from scratch:
    • Root CA installation,
    • Issuing CA installation,
  • CRL and OCSP configuration:
    • distribution point configuration,
    • OCSP responder configuration,
  • deployment of user and device certificates:
    • autoenrollment,
    • Smart Card Logon deployment,
  • CA backup and recovery:
    • failure simulation,
    • PKI infrastructure restoration.

What are the prerequisites for participating in the training?

icon

Windows Server basics - You should be comfortable navigating Windows Server, understand server roles and features, and be able to perform basic server and administrative service configuration.

icon

Active Directory knowledge - You should understand how an Active Directory domain, OUs, GPOs, and service accounts work, because the course covers CA integration and certificate autoenrollment.

icon

Networking and DNS basics - You should know TCP/IP, DNS, and network addressing basics so you can understand CDP and AIA publishing, OCSP operation, and communication between servers and clients.

icon

Cryptography basics - You should understand public and private keys, digital signatures, and certificates so you can work more effectively with templates, CAs, and revocation mechanisms.