Configure Role for ADCS Failover

  1. In the Failover Cluster Management snap-in, right-click Role and select Configure Role

  2. On the Before you Begin page, click Next

  3. From the role list, select Generic Service and click Next

image-20251110-105506.png

Figure 106: Select Role window

  1. From the service list, select Active Directory Certificate Services and click Next

  2. On the Client Access Point page, enter the role name in the Name field and click Next

image-20251110-105522.png

Figure 107: Client Access Point window

  1. Select the disk storage that is still mounted to the node and click Next

  1. Configure a shared registry hive, select the Add button, enter

SYSTEM\CurrentControlSet\Services\CertSvc and click OK

image-20251110-105546.png

Figure 108: Replicate Registry Settings window

  1. Click Next on the Confirmation page

  1. Click Finish to complete the failover role configuration

  2. Open the Failover Cluster Manager and verify that the newly created Roles Status is in the

    Running state and Green

  3. The AD CS Failover got configured successfully. At this stage, you can move the

    certification authority between all nodes.