The Network Device Enrollment Service (NDES) extends Microsoft AD CS with SCEP support, but there are several architectural and operational considerations:
Policy configuration: NDES configurations are closely tied to specific CA, certificate template, and enrollment settings, which can increase administrative complexity.
Additional infrastructure: Depending on the required separation of use cases, additional NDES or Windows Server instances may be required.
High availability: High-availability designs for NDES require additional architectural measures because enrollment state and challenge handling must be considered across instances.
Cryptographic limitations: The supported cryptographic options depend on the Windows, NDES, and certificate template configuration in use.
For organizations with broader automation, scalability, and cryptographic requirements, it may therefore be useful to evaluate modern PKI interfaces and architectures such as SCEP, EST, ACME, CMP, and REST-based automation.