Configure the NDESDeviceAdmin Account with Enroll Permission to the IPsec (Offline Request) Certificate

  1. Log into the CA server using the domain account.

  2. Select Certification Authority from the Tools menu on the Server Manager window.

  3. Expand the server on the left pane, then right-click on Certificate Templates and select Manage.


tmp3gmdrwow.jpg

Certificates Templates Window


  1. Right-click on IPSec (offline request) Template Display Name and select Properties.

  2. Click on the Security tab and select Add button.

  3. On the Select Users, Computers, Service Accounts, or Groups text box, type the name of the NDESDeviceAdmin account, select Check Names, and after finding select OK.


tmpc73kqffu.jpg

IPSec (Offline request) Properties Window


  1. Select the NDESDeviceAdmin account and verify the Allow check box that corresponds to Enroll is selected.

  2. Select Apply and then select OK.