windows-itpro-docs/windows/security/operating-system-security/network-security/windows-firewall/checklist-implementing-a-certificate-based-isolation-policy-design.md
2023-05-24 16:42:58 -04:00

2.3 KiB

title, description, ms.prod, ms.topic, ms.date
title description ms.prod ms.topic ms.date
Checklist Implementing a Certificate-based Isolation Policy Design Use these references to learn about using certificates as an authentication option and configure a certificate-based isolation policy design. windows-client conceptual 09/07/2021

Checklist: Implementing a Certificate-based Isolation Policy Design

This parent checklist includes cross-reference links to important concepts about using certificates as an authentication option in either a domain isolation or server isolation design.

Note

Complete the tasks in this checklist in order. When a reference link takes you to a procedure, return to this topic after you complete the steps in that procedure so that you can proceed with the remaining tasks in this checklist

Checklist: Implementing certificate-based authentication

Task Reference
Review important concepts and examples for certificate-based authentication to determine if this design meets your implementation goals and the needs of your organization. Identifying Your Windows Defender Firewall with Advanced Security Deployment Goals
Certificate-based Isolation Policy Design
Certificate-based Isolation Policy Design Example
Planning Certificate-based Authentication
Install the Active Directory Certificate Services (AD CS) role as an enterprise root issuing certification authority (CA). This step is required only if you haven't already deployed a CA on your network.
Configure the certificate template for workstation authentication certificates. Configure the Workstation Authentication Certificate Template
Configure Group Policy to automatically deploy certificates based on your template to workstation devices. Configure Group Policy to Autoenroll and Deploy Certificates
On a test device, refresh Group Policy and confirm that the certificate is installed. Confirm That Certificates Are Deployed Correctly