Checklist Implementing a Certificate-based Isolation Policy Design (Windows 10)
Checklist Implementing a Certificate-based Isolation Policy Design
1e34b5ea-2e77-4598-a765-550418d33894
brianlic-msft
Checklist: Implementing a Certificate-based Isolation Policy Design
This parent checklist includes cross-reference links to important concepts about using certificates as an authentication option in either a domain isolation or server isolation design.
Note
Complete the tasks in this checklist in order. When a reference link takes you to a procedure, return to this topic after you complete the steps in that procedure so that you can proceed with the remaining tasks in this checklist
Review important concepts and examples for certificate-based authentication to determine if this design meets your deployment goals and the needs of your organization.
[Identifying Your Windows Firewall with Advanced Security Deployment Goals](identifying-your-windows-firewall-with-advanced-security-deployment-goals.md)
Install the Active Directory Certificate Services (AD CS) role as an enterprise root issuing certification authority (CA). This step is required only if you have not already deployed a CA on your network.
[Install Active Directory Certificate Services](install-active-directory-certificate-services.md)
Configure the certificate template for workstation authentication certificates.
[Configure the Workstation Authentication Certificate Template](configure-the-workstation-authentication-certificate-templatewfas-dep.md)
Configure Group Policy to automatically deploy certificates based on your template to workstation computers.
[Configure Group Policy to Autoenroll and Deploy Certificates](configure-group-policy-to-autoenroll-and-deploy-certificates.md)
On a test computer, refresh Group Policy and confirm that the certificate is installed.
[Confirm That Certificates Are Deployed Correctly](confirm-that-certificates-are-deployed-correctly.md)