How to Duplicate and Publish an AD CS Certificate Template
Applies to: Windows Server 2019, 2022 and 2025.
Duplicating a built-in template preserves the original while allowing controlled validity, key usage, subject and enrollment permissions.
PKI changes affect trust across the organization. Use an approved certificate policy, offline backups and separation of duties. Visit networkmanager.info.
Prerequisites
- Use an Enterprise CA.
- Define purpose and EKUs.
- Create enrollment groups.
- Choose client and CA compatibility levels.
Procedure
Step 1: Open templates
Launch management console.
certtmpl.mscStep 2: Duplicate a template
Choose Web Server, Computer or another close base and set compatibility first.
Step 3: Configure crypto
Set provider, key size, hash, validity and renewal.
Step 4: Configure subject
Prefer AD-built subjects; use supply-in-request only under tight control.
Step 5: Set permissions
Grant Read and Enroll to approved groups.
Step 6: Publish
In certsrv.msc select Certificate Templates, New, Certificate Template to Issue.
Verification
Confirm template is available on the CA.
certutil -CATemplatesRollback and recovery
Remove the template from issuance first. Delete the duplicate only after reviewing active certificates.
Security notes
Supply in request can allow dangerous subject names when enrollment is broad.
Official references
Explore Netcloud24 Canada.