Scenario
User certificates issue correctly, but domain computers never enroll for the expected machine certificate.
Recommended Resolution Path
- Compare template permissions and autoenrollment policy scope for computers versus users.
- Check whether the machine template supersedence or subject requirements are unmet.
- Review client autoenrollment event logs on an affected computer.
- If one OU is affected, inspect GPO scope before blaming the CA.
Technician Notes
Capture the exact scope of impact, confirm which dependency failed first, and document whether the issue reflects broader domain or server drift.
- Log in to post comments