Yes, certificate templates are stored in Active Directory. However, there are several limitations to consider:
Automation of template creation and modification: There is no standard built-in workflow for fully automating the creation and modification of certificate templates, which means changes often require administrative intervention.
Centralized configuration: Certificate templates are centrally available within the Active Directory environment and must be carefully designed to meet different use cases and security requirements.
Additional infrastructure: Depending on architectural and separation requirements, additional Certification Authorities and Windows Server instances may be required.
Modern PKI solutions can provide greater flexibility and automation for managing certificate policies and templates. This can reduce administrative effort, lower the risk of configuration errors, and improve operational efficiency.