Active Directory Certificate Services (AD CS) primarily uses Microsoft-specific enrollment mechanisms such as RPC/DCOM and MS-WCCE. These interfaces are closely tied to Microsoft and Active Directory environments and are less suitable for many cloud-native and heterogeneous use cases.
SCEP can also be provided in Microsoft environments through NDES, but this requires additional infrastructure and configuration.
AD CS does not natively provide several interfaces commonly used in modern PKI automation scenarios, including:
- Enrollment over Secure Transport (EST)
- Automatic Certificate Management Environment (ACME), although third-party solutions are available
- Certificate Management Protocol (CMP)
- General-purpose REST- or SOAP-based certificate enrollment interfaces
Third-party solutions can be used to add some of these capabilities. MTG Corporate PKI supports modern automation interfaces such as ACME, EST, CMP, SCEP, and REST, allowing certificates to be integrated into Windows, Linux, network, IoT, cloud, and application environments.