Configuring a Template and Permissions on the Active Directory Certificate Services (AD CS) Server

Technical Paper: Integrating with Active Directory Certificate Services (AD CS) Using Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
Jamf AD CS Connector
ft:locale
en-US

Jamf Pro's computer or mobile device configuration profile certificate settings include a field for specifying the template to be used when requesting a certificate from Active Directory Certificate Services (AD CS). The specified template is applied to the computer or mobile device when the certificate is requested, which occurs after the configuration profile, and its payloads, have been deployed on the computer or mobile device.

The template settings are managed on the AD CS server, not the Jamf AD CS Connector server.

Requirements
Ensure the requirements for distributing configuration profiles are met. See the following from the Jamf Pro Documentation:
  1. On the AD CS server, go to Server Manager > Tools > Certification Authority to open the Certification Authority Microsoft Management Console (MMC).
  2. Double-click the certificate authority name, right-click Certificate Templates, and then select either New or Manage.
  3. In the Certificate Templates console, make note of the Template name in the General tab for your template. This template name will be supplied to Jamf Pro when configuring the Certificate or SCEP payload in a configuration profile.
  4. On the Subject Name tab, select Supply in the request.
  5. On the Security tab, give the Jamf AD CS Connector host the Enroll permission.
    Note:When Supply in the request is selected for the certificate subject, Jamf recommends that you remove the "enroll" permission from all other users and groups, except the Jamf AD CS Connector. Remove "Domain Computer" and "Domain Users" if they are listed.
  6. If you are using automatic certificate revocation, grant the Jamf AD CS Connector's computer name the Issue and Manage Certificates permission on the CA Properties Security tab.