PKI AND CERTIFICATES

Active Directory Certificate Services and PKI Playbook

Understand trust chains, certificate authorities, templates, CRLs and safe certificate deployment before installing an enterprise CA.

Servers textbookChapter 7

Learning objectives

  • Explain the main purpose of Active Directory Certificate Services and PKI in plain language.
  • Explain how domain controllers, DNS, users, groups, OUs and Group Policy fit together.
  • Use evidence to separate a design problem from a configuration or physical fault.
  • Describe the business impact of a failure and the evidence required for handover.

Why this matters in a real company

For a company, this is about controlling who can sign in, which computers are trusted and what staff are allowed to access. A clean identity design reduces password chaos, orphaned accounts and uncontrolled administrator access.

Course: Servers and Virtualization Technical Textbook

PLAIN ENGLISH

Technical terms used in this chapter

You do not need to memorise the jargon first. Understand what each term does and why somebody running a company would care about it.

Active Directory

Active Directory

Microsoft's central directory for users, computers, groups and access control in a Windows domain.

In everyday business: One staff account can be managed centrally instead of separately on every PC.

Certificate

Digital Certificate

A signed digital identity that binds a name or system to a public key.

In everyday business: Browsers, VPNs and servers use certificates to prove who they are and encrypt connections.

Backup

Backup

An independent recoverable copy of data or system state.

In everyday business: It is the safety net for deletion, corruption, ransomware, hardware loss or major mistakes.

PKI

Public Key Infrastructure

The systems, policies and certificates used to prove identity and build encrypted trust.

In everyday business: It lets company systems trust certificates instead of accepting any device that claims to be legitimate.

NAT

Network Address Translation

A router or firewall function that changes IP addressing as traffic crosses a boundary.

In everyday business: Many private office devices can share one public Internet address.

SAN

Storage Area Network

A dedicated storage network that presents block storage to servers.

In everyday business: Multiple servers can use centrally managed storage without treating it like a normal file share.

RPO

Recovery Point Objective

How much recent data the business can afford to lose.

In everyday business: It determines how often backups or replication need to run.

See the complete plain-English glossary

BUSINESS TRANSLATION

What this means outside the server room

This topic affects the systems staff depend on for sign-in, files, applications and business continuity. The technical design determines how easy the environment is to manage and how painful a failure becomes.

Active Directory

What it means: Active Directory centrally manages users, computers, groups and access in a Windows domain.

In normal business language: Think of it as one employee identity system for the company instead of separate usernames and passwords on every computer and server.

Why the decision matters: Use it when a company needs central sign-in, consistent permissions, controlled administrator access and easier onboarding/offboarding.

DNS

What it means: DNS translates names into IP addresses and also helps many business services locate each other.

In normal business language: It is the company phonebook for systems. Staff type a name such as fileserver or portal instead of remembering a number.

Why the decision matters: Good DNS design reduces configuration mistakes and is especially important for Windows domains, cloud integrations and internal applications.

DHCP

What it means: DHCP automatically gives devices their network settings.

In normal business language: It is like reception assigning each new visitor a desk number and directions automatically instead of somebody configuring every laptop by hand.

Why the decision matters: Use DHCP for normal endpoints and reserve static addressing for infrastructure where predictable addressing is required.

Backup

What it means: A backup is an independent recoverable copy of data or system state.

In normal business language: Think of it as having a duplicate of important company records stored safely away from the live filing cabinet.

Why the decision matters: A backup only counts if it can be restored. Test recovery, not just backup completion.

Replication

What it means: Replication copies data or VM state to another system or location.

In normal business language: It is like keeping a second live copy of the filing room at another branch. It can reduce recovery time, but bad changes can also be copied.

Why the decision matters: Replication improves availability and recovery speed, but it does not replace retention and backup.

Firewall

What it means: A firewall controls which network connections are allowed between users, systems and external networks.

In normal business language: It is a security checkpoint between parts of the company network. It should allow legitimate work while blocking unwanted access.

Why the decision matters: Firewall rules should describe real business flows such as 'staff may reach accounting on HTTPS', not unexplained broad permits.

Simple two-tier PKI concept
Offline Root CATrust anchor Enterprise Issuing CAIssues operational certificates Users / ComputersServers / Network Devices

What AD CS provides

Microsoft describes AD CS as the Windows Server role for issuing and managing PKI certificates used for authentication, encryption and digital signatures.

Root CA vs issuing CA

A two-tier design can keep the root CA offline and use one or more issuing CAs for day-to-day enrollment. This reduces exposure of the trust anchor, but adds operational complexity. Small environments should still design lifecycle, backup and revocation before deployment.

Certificate template questions

  • Who can enroll?
  • What key usage is allowed?
  • What subject/SAN values are permitted?
  • What validity/renewal period?
  • Is auto-enrollment appropriate?

Revocation

Clients need reachable revocation information where the application validates it. A CA is not fully designed until CRL/CDP/AIA publication and renewal are understood.

CA backup

Back up the CA database, private key and configuration according to Microsoft guidance. Protect the private key as highly sensitive material.

What fails

  • Installing an enterprise root CA on a general-purpose application server.
  • Publishing certificate templates too broadly.
  • Letting CRLs expire.
  • Renewing CA certificates without planning chain impact.
PRACTICAL WORK

Hands-on lab

Build a small lab domain with one DC and one client. Create two OUs, two security groups and two users. Join the client, then prove which DNS server it uses and which GPOs apply.

Troubleshooting exercise

A user can sign in locally but cannot sign in with the domain account. Check DNS, network reachability, time, domain membership and DC service health in that order.

Chapter field checklist

  • I can explain the subject without relying only on acronyms.
  • I can draw or describe the main traffic, storage, power or service path.
  • I know what normal operation should look like.
  • I know which logs, counters or test results prove the result.
  • I can explain the business impact if this component fails.
  • I would document the final configuration and evidence at handover.

Chapter summary

Active Directory Certificate Services and PKI Playbook should now be understood as a business service with a technical implementation, not simply a collection of commands or product names. The important habit is to know the purpose, understand the dependencies, measure the result and document what was proven.

Technical references

Use the current product documentation and project requirements for production work.