Area 05 / 12
AD Certificate Services
AD Certificate Services is Tier 0, and a single misconfigured template can hand an attacker a domain admin certificate. This area walks the ESC1–ESC8 misconfigurations, disables the dangerous CA flag, requires manager approval and enforces authentication on the CA web endpoints.
Start the pathLearning path
0/4 done- 01AD CS hardening: closing ESC1-ESC8 misconfigurationsHarden Active Directory Certificate Services against ESC1-ESC8 misconfigurations with template controls, EPA, and enrollment monitoring.
- 02Auditing AD CS certificate templates for ESC1-ESC4Audit every AD CS certificate template for ESC1-ESC4: subject flags, EKUs, enrollment rights and template ACLs, with PowerShell and a safe fix order.
- 03Securing AD CS web enrollment against ESC8 and ESC11Close NTLM relay to AD CS: find HTTP enrollment endpoints, enforce HTTPS and EPA, disable NTLM, remove Web Enrollment and enforce RPC encryption.
- 04Strong certificate mapping (KB5014754) in practiceGet certificate authentication ready for KB5014754 Full Enforcement: SID extension, altSecurityIdentities, KDC events 39/40/41 and the fixes that work.