Short for Active Directory Certificate Services, a Windows Server role that operates a private certificate authority. Because the certificates it issues are not publicly trusted, services needing a public CA, such as Front Door bring-your-own-certificate, refuse them.
Also called Active Directory Certificate Services.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains AD CS in context, with comparison tables and the common traps.
Terms in this definition
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- CA
Entity that issues digital certificates; point-to-site VPN needs one only when clients authenticate with root and client certificates, not when RADIUS or Entra ID is used.
- Trusted services
An ACR option, on by default, letting chosen Azure services, for instance ACR import, Container Instances and Defender for Cloud, get past a registry's firewall rules or private endpoint. App Service isn't covered.
Related terms
- BYOCA
Lets you chain a cloud issuing CA in Microsoft Cloud PKI to an existing private CA, AD CS for instance; that private CA signs the CSR that Intune generates.
- Microsoft Trusted CA List
Certificate authorities whose root certificates Front Door will accept when you bring your own certificate. Self-signed certificates and private CAs like AD CS are excluded.
- NDES
Network Device Enrollment Service. Part of AD CS, it processes SCEP certificate requests for a Microsoft certification authority, so Intune SCEP profiles using such a CA depend on it as well as on the Certificate Connector.