Ask the Expert

How to revoke and delete Active Directory user certificates

When you delete a user from active directory 2003, is it possible to configure the system so the user's certificate on the CA will automatically get revoked or deleted as well?

Requires Free Membership to View

The Active Directory (AD) implementation used with Windows Server 2003 has a feature called, autoenrollment that you can configure to automatically revoke and delete user certificates on the Certificate Authority (CA).

To set up the autoenrollment feature, follow these steps:

  1. Go to the Group Policy Objects (GPO) settings, and select Properties for the object, then click Edit and drill down until you get to "Object Type."

  2. Right click on "Autoenrollment Settings" and go to "Properties."

  3. Check "Enroll Certificates Automatically" and once the box appears, select the two checkboxes underneath it.

  4. Click OK and you're done.

Visit the Microsoft Web site for a more in depth explanation (http://microsoft.com).

The autoenrollment feature should add a little bit of extra system access security. If you choose not to use it, you have to delete all user accounts from the system manually. Also, remember that loose certificates sitting on compromised machines, stolen laptops or other errant equipment, can be exploited by users whose accounts may be gone, but whose ghosts aren't.

This was first published in February 2006