PKI, AD CS, and certificate-based authentication

Certificates are how you get phishing-resistant sign-in and real network access control, but only if the PKI underneath is designed and secured properly. We build or remediate your internal PKI on Active Directory Certificate Services, then put it to work: certificate-based authentication to Entra ID, and 802.1X so only known, healthy devices get onto the wired and wireless network.

What's included

  • AD CS design or review: offline root and issuing CA hierarchy, CRL/OCSP, key protection (HSM or KSP)
  • AD CS hardening: ESC1-ESC8 misconfiguration review and remediation, enrollment-agent and template lockdown, auditing
  • Certificate templates and autoenrollment for users, devices, and servers
  • Entra ID certificate-based authentication (CBA): authentication policies, username bindings, phishing-resistant MFA strength
  • SCEP / PKCS certificate deployment via Intune for cloud-managed devices
  • 802.1X for wired and wireless: NPS / RADIUS (or cloud RADIUS), connection-request and network policies, machine and user auth
  • Dynamic VLAN assignment, guest and quarantine handling, and MAB fallback for non-802.1X devices
  • Certificate lifecycle: renewal, revocation, and monitoring
  • Runbooks and an operations handover

How we work

01

Scope

A fixed statement of work: what we will do, what you receive, and the timeline. Agreed before any work starts.

02

Execute

We do the work in your tenant with least-privilege access, with updates at defined checkpoints, not radio silence.

03

Hand off

Documentation, runbooks, and a walkthrough so your team can operate what we built.

PKI & Certificate-Based Authentication: common questions

Can you do Entra certificate authentication without on-premises AD CS?

Entra CBA needs certificates from a trusted issuer, that can be your AD CS, a third-party CA, or a cloud PKI. We help you choose based on what you already run and where devices are managed.

Is our current Certificate Services setup a security risk?

Often, yes. AD CS misconfigurations, the ESC1 through ESC8 class, are a common privilege-escalation path. This engagement includes a review and remediation of those.

Do we need new network hardware for 802.1X?

Usually not. Most managed switches and business access points already support it. We confirm during scoping and flag anything that needs replacing.

How does this relate to your network engineering service?

802.1X is the access-control layer on top of the switching and wireless design. If you need both, they are scoped together; if the network is already sound, this adds the identity-aware control.

Talk to a senior architect about pki & certificate-based authentication

A short call to understand your environment, then a fixed-scope proposal. Based in Denver, Colorado; we work with clients across the US remotely.