Autoenrollment under MTG CLM Control

Microsoft Active Directory already provides native certificate autoenrollment for Windows users and computers. Windows Autoenrollment Connector (AEC) puts your MTG CLM instance in charge of that process. This way, certificates can be issued automatically through standard Group Policy while their lifecycle is centrally managed in MTG CLM. The result is a smoother user experience, less manual administration and greater visibility & control across your certificate environment.

Overview

AEC connects MTG CLM with Active Directory’s built-in autoenrollment capabilities.

Domain-joined Windows users and computers continue to receive certificates through the standard Microsoft enrollment process they already support. No new enrollment workflow is introduced for end users. Behind the scenes, MTG CLM becomes the central management layer for certificates issued through autoenrollment. This gives administrators a unified view of issued certificates and a consistent way to manage their lifecycle across the environment.

What You Get

One Enrollment Path for Users and Computers

Dedicated autoenrollment templates cover both, so a single integration serves the entire domain fleet.

Central Certificate Lifecycle Management

Certificates issued through autoenrollment are managed from MTG CLM, one inventory and one set of lifecycle actions, instead of being tracked CA by CA.

Built on Trusted Active Directory Security Mechanisms

AEC authenticates with Kerberos, reads the directory over TLS-protected LDAP and runs under two dedicated least-privilege accounts: aec-service for the connector itself and aec-ldap-user for directory access.

Automatic Trust Distribution Included

Root and subordinate CA certificates are pushed to clients through the same Group Policy infrastructure as the enrollment policies.

How It Works

AEC fits into the existing Active Directory and Group Policy architecture rather than replacing it. AEC runs on a Windows host registered in DNS and authenticates to Active Directory over Kerberos.

  • Directory lookups go through TLS-secured LDAP using a dedicated read account.

  • Certificate templates define which certificates users and computers are allowed to receive automatically.

  • Group Policy enrollment policies, under Computer Configuration and User Configuration, enable autoenrollment.

  • Root and Sub CA certificates are distributed to clients through Group Policy.

  • Windows clients refresh their policies and automatically request certificates asssigned tot hem. Once configured, certificate enrollment becomes part of the normal Windows domain experience.

Deployment at a Glance

AEC is designed to work with infrastructure you already operate. There is no need to redesign or restructure Active Directory. For a healthy domain environment, deployment is primarily a configuration exercise rather than a new infrastructure project. The setup process is clearly defined:

  • Prerequisites: Verify or install Active Directory Domain Services, promote a domain controller if required, install the Certification Authority management tools, configure TLS for LDAP and verify connectivity.

  • Main AEC Guide: Create the two dedicated service accounts, register the AEC host in DNS, configure AEC and Kerberos, publish user and computer certificate templates, configure the enrollment policies and update clients so they can begin requesting certificates.

No restructuring of AD required. If the domain is healthy, the connector is a configuration exercise, not an infrastructure project.

The Benefit

By connecting Active Directory with MTG CLM, organizations can combine the convenience of native Windows autoenrollment with centralized certificate lifecycle management.