AD CS Web Enrollment is a web-based certificate issuance interface in Active Directory Certificate Services. It can become a high-risk target when it accepts relayable authentication, because an attacker may use coerced credentials to request certificates that enable persistent impersonation or broader authentication abuse.
What AD CS Web Enrollment Is and Why It Matters
AD CS Web Enrollment is a browser-based front end for requesting certificates from Active Directory Certificate Services. It matters because the convenience of web enrollment can also expose the certificate issuance path to misuse when authentication and authorization are not tightly constrained.
At a high level, the service sits between a requester and certificate authority policy. That makes it useful for legitimate enrollment workflows, but it also means the enrollment endpoint can become part of an abuse chain if weak authentication methods, overly broad templates, or permissive issuance rules are present.
How Web Enrollment Fits into Certificate-Based Trust
Web enrollment is not the certificate authority itself, but it can influence who gets a certificate and under what identity attributes. In practice, that means the interface participates in trust establishment: a successful request can result in a credential that later authenticates to systems, services, or directory-backed applications.
Because certificates are identity-bearing material, the issuance step has security consequences beyond the web page. If an attacker can reach the enrollment path with a relayed or coerced authentication context, the resulting certificate may outlive the original session and be usable in other authentication flows.
For that reason, certificate enrollment should be understood as an access and trust decision, not just a web form. The business value is convenience and automation, but the security cost is that issuance becomes a high-value control point that must faithfully bind the certificate to the intended requester.
Common Failure Modes and Abuse Paths
The most important failure mode is when the web enrollment endpoint accepts authentication that can be relayed, reused, or otherwise substituted by an attacker. In that case, the requester identity seen by the server is no longer trustworthy enough to safely authorize certificate issuance.
Other common weaknesses include broad enrollment permissions, templates that permit subject alternative names or other identity overrides, and inconsistent separation between requester identity and the identity that will be asserted by the certificate. Those conditions can turn an administrative convenience into a durable impersonation primitive.
Web enrollment also becomes riskier when certificate templates or policy settings allow long-lived certificates with broad authentication scope. Once issued, the certificate may be used for persistence, lateral movement, or authentication against services that trust the certificate chain without re-checking the original enrollment context.
Operational Meaning for Administrators and Defenders
Administrators should treat AD CS Web Enrollment as part of the broader identity and access surface, not as a simple self-service portal. Its configuration determines whether certificate issuance reflects genuine authorization or merely whatever authentication material reaches the endpoint.
Defenders should pay close attention to enrollment templates, issuance rights, and the authentication methods accepted by the web interface. The goal is to ensure that only intended identities can request only intended certificate types, with no easy path from unauthenticated or relayed access to a trusted certificate.
In mature environments, web enrollment is useful when it supports controlled workflows. It becomes dangerous when convenience outruns policy, because the certificate it issues can function as a stronger and more persistent proof of identity than the original web session that triggered it.
Risk and Threat Considerations
AD CS Web Enrollment is high risk when an attacker can coerce or relay authentication into the enrollment flow, because the service may issue a certificate that can be used for persistent impersonation. The danger is not the web page itself, but the trust upgrade that happens if an untrusted enrollment path can mint a durable certificate.
Failure mechanism: Relayed authentication, permissive templates, or weak requester-to-subject binding can let an attacker obtain a certificate that represents a more trusted identity than the one originally presented.
Impact: The attacker may gain persistent authentication capability, bypass normal password or session defenses, and reuse the certificate to access directory-backed services or other systems that trust certificate-based identity.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Web enrollment issues certificates that function as authenticators. |
| IA-9 — Service Identification and Authentication | AD CS web enrollment supports machine and service-style authentication flows. | |
| Recommendation — Restrict certificate issuance, rotation, and revocation so enrollment cannot mint durable abuse paths. Bind certificate issuance to strong service authentication and prevent relayed enrollment requests. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Relayable enrollment weakens the authentication step that gates certificate issuance. |
| NHI-05 — Overprivileged NHI | Overbroad certificate templates can grant more authentication power than intended. | |
| Recommendation — Block relayable authentication paths before certificates can be issued through web enrollment. Constrain certificate templates so issued certificates carry only the minimum required privileges. | ||
| MITRE ATT&CK | T1552 — Unsecured Credentials | Issued certificates can become stolen or abused credential material for persistence. |
| Recommendation — Detect certificate abuse as credential access and hunt for unauthorized certificate issuance patterns. | ||
Related resources from NHI Mgmt Group
- What should teams do first when AD CS Web Enrollment reports the target certificate authority as offline on a separate server?
- What do administrators often get wrong when configuring AD CS Web Enrollment on a server separate from the CA?
- Why does AD CS Web Enrollment need delegated access to the certificate authority in a split-server setup?
- What happens when AD CS Web Enrollment is deployed on a separate server without the required delegation?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org