You can configure the PKI certificates settings in Jamf Pro to use AD CS as a certificate authority.
Adding AD CS as a certificate authority in Jamf Pro requires you to configure the AD CS integration settings and the JamfAD CS Connector settings. This involves defining the location of the connector and AD CS servers and adding client and server certificates to permit authentication between Jamf Pro and the connector.
After you add AD CS as a certificate authority in Jamf Pro, you can use the PKI certificates settings in Jamf Pro to view and edit information about the CA. In addition, you can use the PKI certificates settings to view information about the active, expired, or inactive AD CS certificates that have been distributed to devices via configuration profiles.
In Jamf Pro, click Settings in the sidebar.
In the Global section, click PKI certificates .
Click Configure New Certificate Authority.
Select Active Directory Certificate Services (AD CS) and click Next.
In the AD CS Server Integration area, do the following:
Enter a display name for the integration in the Display Name for Integration field.
Enter the name of the certificate authority in the CA Name from AD CS Server field.
The CA name is the common name of the issuing certification authority.
Enter the fully qualified domain name of the server that hosts AD CS in the Fully Qualified Domain Name field.
In the Jamf AD CS Connector area, select or deselect the Automatic certificate revocation checkbox as needed.
When automatic certificate revocation is enabled, certificates issued by AD CS are queued for revocation immediately after the Wipe Computer, Wipe Device, or Unmanage Device action is taken. When computers or mobile devices fall out of the scope of the configuration profile that issues the certificate, the certificate will be queued for revocation after the computers or mobile devices acknowledge the remove profile command.
Note:
If automatic certificate revocation is enabled and you disable it, any certificates that have been marked for revocation will continue to be revoked after revocation is disabled.
Click Outbound as the connector mode.
Enter the API Client ID that you created earlier in the Client ID field.
Click Save .
Take note of the AD CS integration ID, which you will need for the -adcsId parameter when installing the JamfAD CS Connector.
The -adcsId is the number at the end of the URL displayed in your browser's address bar, typically "3" for a new installation.
AD CS is listed as a certificate authority on the Certificate Authorities tab.