Forum Discussion

prakashx86's avatar
prakashx86
Copper Contributor
Nov 13, 2025

Access denied. 0x80090010 Enroll cert of Windows hello for Business with on-prem PKI CA Server

We have created Certficate Template from on-prem CA Server ( Windows server 2019 ) using this link : https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/rdp-sign-in?tabs=intune

However We can not Enroll Certificate Windows Hello for Business Certificate from User's Desktop ( Windows 11 ) and every time error occurred or Access Denied (

Certificate enrollment for Domain\UserName failed to enroll for a WHfBCertificateAuthentication certificate with request ID N/A from -ERCA.Domain.local\Domain-ERCA-CA-1 (Access denied. 0x80090010 (-2146893808 NTE_PERM))

 

 

We have also given Read and Enroll permission to EveryOne and Autheticated Users from CA Certficiate template , but still same erro

 

 

Please advise if anything more can be done to resolve this issue.

No RepliesBe the first to reply