In each Windows domain enrollment endpoint, import the root certificate of the CA that will issue certificates for the enrollment service.

To import the CA certificate

  1. Log in to the server hosting Active Directory.
  2. Open the Group Policy Management administrative tool. Select Start > Windows Administrative Tools > Group Policy Management.
    The Group Policy Management dialog box appears.
  3. In the tree view, expand the Domain Controller you will modify.
  4. Right-click Default Domain Policy > Edit. The Group Policy Management Editor dialog box appears.
  5. In the tree view, expand Computer Configuration > Policies > Windows Settings > Security Settings > Public Key Policies.
  6. Right-click Trusted Root Certification Authorities and select Import.
    The Certificate Import Wizard dialog box appears.
  7. Click Next.
    The File to Import page appears.
  8. Click Browse and select the root certificate of the CA that will issue certificates for the enrollment service.
  9. Click Next.
    The Certificate Store page appears.
  10. The Certificate Store field is automatically set to Trusted Root Certification Authorities. Click Next.
    The Completing the Certificate Import Wizard page appears.
  11. Click Finish.