PrepAway - Latest Free Exam Questions & Answers

You need to ensure that all of the client computers automatically receive certificates based on Template1

Your network contains a server named Server1 that runs Windows Server 2008 R2
Standard. Server1 has the Active Directory Certificate Services (AD CS) role installed.
You configure a certificate template named Template1 for autoenrollment.
You discover that certificates are not being issued to any client computers. The event logs
on the client computers do not contain any autoenrollment errors.
You need to ensure that all of the client computers automatically receive certificates based
on Template1.
What should you do?

PrepAway - Latest Free Exam Questions & Answers

A.
Modify the Default Domain Policy Group Policy object (GPO).

B.
Modify the Default Domain Controllers Policy Group Policy object (GPO).

C.
Upgrade Server1 to Windows Server 2008 R2 Enterprise.

D.
Restart Certificate Services on Server1.

Explanation:
http://technet.microsoft.com/en-us/library/cc731522.aspx
Configure Certificate Autoenrollment
Many certificates can be distributed without the client even being aware that enrollment is
taking place. These can include most types of certificates issued to computers and services,
as well as many certificates issued to users.
To automatically enroll clients for certificates in a domain environment, you must:
Configure a certificate template with Autoenroll permissions.
Configure an autoenrollment policy for the domain.
To configure autoenrollment Group Policy for a domain
1. On a domain controller running Windows Server 2008 R2 or Windows Server 2008, click
Start, point to

Administrative Tools, and then click Group Policy Management.
2. In the console tree, double-click Group Policy Objects in the forest and domain containing
the Default
Domain Policy Group Policy object (GPO) that you want to edit.


Leave a Reply