Issue the Key Recovery Agent Certificate

  1. Open the command prompt and run the certmgr.msc command.

image-20250805-072516.png


"Certificate Manager" Window

  1. Right-click Personal node. Select All Tasks, then select Request new certificate…

image-20250805-072548.png


"Certificate Manager" Window

  1. Click Next.

image-20250805-072609.png


"Before You Begin" Window

  1. Select Certificate Enrollment Policy and click Next.

If you are using smartcard authentication, the prompt will appear on the PIN Pad device to insert the smartcard and enter the PIN. Then, press the OK button on the PIN Pad.

  1. Select the above-created Key Recovery Agent checkbox and click Enroll.

image-20250805-072635.png


"Certificate Enrollment" Window

  1. Verify the Enrollment is pending and click Finish.