Event banner
AD CS enhancements, innovations, and security
Event details
Explore the latest innovations in Active Directory Certificate Services (AD CS) as we delve into key areas such as CRL partitioning, the 4K extension limit, enhanced CA audit events, and ADCS security hardening techniques. Join us for an in-depth discussion on these topics and learn how to leverage them in your AD CS deployments.
Speakers: Tanya Jha, Thirunadha Reddy
This session is part of Windows Server Summit 2025. Have a question? Q&A is open throughout the week. Post your questions and feedback in the Comments below.
12 Comments
- Tanya_Jha
Microsoft
Thanks for joining us for Windows Server Summit! If you have any feedback about AD, AD CS or about this session, please email ADFeedback@microsoft.com.
Here’s a list of all the links we discussed during today's session:
- Install the necessary Windows Updates to enable the 4K to 16K expansion: aka.ms/CertExtensionLimit
- All the CA audit events are documented here – aka.ms/MonitorPKI
- Securing Certificate Templates: Learn more at aka.ms/SecureCertTemplates
- Mitigating NTLM Relay Attacks on AD CS: Apply mitigation steps published at aka.ms/KB5005413
- Strong Certificate Mappings:
- Certificate-based authentication changes on Domain Controllers: https://aka.ms/KB5014754
- Intune related changes:
- aka.ms/IntunePKCSProfile: Connector update to include the SID extension in the certificates
- aka.ms/IntuneSCEPProfile: SID info will be added as an alternate name in SAN extension
Thank you!
- Heather_Poulsen
Community Manager
Thanks for tuning in! We hope you enjoyed this session. Q&A will remain open through Friday.
The Windows Server Summit 2025 continues.
Up next: Beyond the MCSE: Windows Server training and certification - Tanya_Jha
Microsoft
We are actively working on adding PQC support to ADCS. Please stay tuned to official Microsoft announcements for updates!
- Heather_Poulsen
Community Manager
Welcome to AD CS enhancements, innovations, and security and Windows Server Summit 2025! Have a question? Post it here in the Comments so we can help. Let’s make this an active Q&A!
If you prefer, you can also watch it on LinkedIn: AD CS enhancements, innovations, and security | LinkedIn
All of today's sessions will be available on demand immediately after airing. You'll see auto-generated captions during our live broadcasts, and we will update those with human-generated captions by the end of the week. Q&A will be live during the sessions, and we'll leave it open through the end of the week. - PatrickICopper Contributor
Do you plan SHA3 support ?
- Tanya_Jha
Microsoft
At this time, we haven’t evaluated that specifically, but I appreciate you raising it. I’ll make sure to capture this feedback and share it with my team for consideration!
Do you plan a ACME enrollment method for ADCS ?
- PatrickICopper Contributor
Already available on GitHub (2 versions). for example, https://github.com/glatzert/ACME-Server-ADCS
- CharlesFCPCBrass Contributor
Yes there are already custom tooled OSS solutions out on GitHub, but lots of enterprises would much rather have an in-box supported solution that gets installed with/along side ADCS.
- poliveirasilvaCopper Contributor
Is there a timeline for AD CS to support Post Quantum Cryptography (PQC)? What AD CS roles will support PQC?