Active Directory Certificate Services (AD CS) Integration: Setup and Configure

By Corey Willis

Learn how to integrate Kandji with Microsoft AD CS

The AD CS integration is configured from the Kandji Integrations marketplace in your Kandji web app. Once the setup is complete, you can manage Kandji AD CS Connector servers, add your AD CS certificate authority (CA) hosts, and create Library Items, all from the AD CS integration page.
The Kandji AD CS Connector (current version - 1.0.0.3) installation media is downloaded during the initial integration setup.

Before You Begin

  • Ensure you have a computer certificate template created in AD CS for use with Kandji.

  • Ensure you have access to the Windows Server designated as the AD CS Connector.

  • To save time, have the Windows server up and running so you're ready to install the AD CS Connector application once you have completed the initial AD CS integration setup.

Setup and Configuration Overview

  1. Complete the initial setup of the AD CS integration.

  2. Download the AD CS Connector installer.

  3. Add a CA server to the AD CS integration.

  4. Install the AD CS Connector on the designated Windows server.

  5. Assign the CA server to the AD CS Connector in the Kandji web app.

  6. Build out Library Items to deliver AD CS certificates to devices.

AD CS Integration Setup

If you do not see the AD CS integration in your Kandji web app, contact your Customer Success Manager or Account Executive for assistance.
  1. Log in to Kandji.

  2. In the left-hand navigation, go to Integrations.

  3. Near the top-right, click Discover integrations.

  4. Find the Active Directory Certificate Services integration and click Add and configure.

  5. In the Welcome window, there are a few links that you can use to learn more about Installing the AD CS Connector on a Windows server and how to create Library Items to deploy AD CS certificates to devices. These support articles can also be found in the Kandji Support knowledge base. Click Get started to continue with the setup process.

  6. In the Download window, click Download connector. You should see an indicator displaying the download progress. Once the download is done, the Kandji ADCS.exe installer file will be in your default downloads folder.

  7. Once the download completes, click Next.

  8. On the Connection pending… screen, you will see a few instructions that need to be performed on the Windows Server designated as the AD CS Connector.

  9. To go back to the main Integrations page, click Close.

  10. An AD CS integration card should be visible on the main Integrations page.

  11. The status will show as Pending installation… until the AD CS Connector has been installed on the Windows server and you have signed in to the AD CS Connector with your Kandji credentials to create the WebSocket connection back to Kandji.

  12. Click on the AD CS integration card to go to the Overview page.

  13. On the Overview page, you can see information about the AD CS Connector that was just added. Most of the details will not be populated until the AD CS Connector is installed on the Windows server and a connection is made back to Kandji.

  1. The domain to which the AD CS Connector server is bound.

  2. The Connector's IP address.

  3. Assigned AD CS servers. Servers can be assigned once the AD CS Connector is connected back to Kandji.

  4. The version of the Windows server where the AD CS Connector is installed.

  5. Status on the connection between Kandji and Kandji AD CS Connector. The status will remain in a Pending state until the Connector is installed on the Windows server and a connection is made back to Kandji.

  6. In the Connector action menu(...), you can view the installation instructions, redownload the connector installer, or delete the connector.

Adding AD CS Certificate Authority Servers

You must define the FQDN in the Server name field in the AD CS servers tray. 
  1. On the AD CS Integration page, click the Servers tab.

  2. In the tray, add the AD CS server(s) that will be used for creating certificates using the format of: ca_server_fqdn\issuing_ca_name (Example: "subordinateca.kandji-adcs.com\QueenBee Issuing CA"). The issuing_ca_name is found in the Certificate Authority Snap-in on the issuing CA Windows server. You will be able to assign the server once the Connector shows a status of Connected.

  3. Click Add.

  4. The status for the AD CS server will show as Disconnected until assigned to an AD CS Connector. Once the AD CS Connector status shows Connected, you can assign the AD CS CA server(s) to the AD CS Connector. You can edit or delete the AD CS server from the action menu () on the AD CS server card.

At this point, you are ready to hop over to the Connector Installation support article to install the AD CS Connector on the Windows server and establish a connection back to Kandji.

Assigning an AD CS server to a Connector

Once the AD CS Connector status shows as Connected, you can assign an AD CS server to the Connector.

  1. On the AD CS Integration Overview page, click the action menu()on the Connector card.

  2. Click Assign servers.

  3. Select the AD CS server from the list.

  4. Click Add.

    There should now be an AD CS server assigned to the Connector.

At this point, you are ready to start building out Library Items to deploy AD CS certificates to devices.

Adding Additional Connectors

If needed, additional AD CS Connectors can be added to the AD CS integration.

  1. In Kandji, navigate to Integrations and select the AD CS Integration card.

  2. Click Add connector.

  3. A new connector will appear in a Pending state awaiting AD CS service assignment.

  4. From the action menu (), you can view install instructions, redownload the connector installer, or remove the connector entirely.

Removing the Integration

This integration is a requirement to issue AD CS certificates to your Apple fleet. Deleting this integration cannot be undone.

Use the steps below to remove an Active Directory Certificate Services Connector from your Kandji tenant.

  1. In Kandji, navigate to Integrations.

  2. Click on the Active Directory Certificate Services integration that you want to remove.

  3. On the main Active Directory Certificate Services page, click the Action menu (…) and click Delete integration.

  4. In the Delete AD CS Integration window, click the Delete integration button. Once the integration is removed, you will be taken back to the main Integration page.