Problem solve Get help with specific problems with your technologies, process and projects.

How to revoke and delete Active Directory user certificates

In this Ask the Expert Q&A, our identity and access management expert examines how to set up Active Directory autoenrollment feature to revoke and delete user certificates on the Certificate Authority (CA) automatically.

When you delete a user from active directory 2003, is it possible to configure the system so the user's certificate on the CA will automatically get revoked or deleted as well?

The Active Directory (AD) implementation used with Windows Server 2003 has a feature called, autoenrollment that...

you can configure to automatically revoke and delete user certificates on the Certificate Authority (CA).

To set up the autoenrollment feature, follow these steps:

  1. Go to the Group Policy Objects (GPO) settings, and select Properties for the object, then click Edit and drill down until you get to "Object Type."

  2. Right click on "Autoenrollment Settings" and go to "Properties."

  3. Check "Enroll Certificates Automatically" and once the box appears, select the two checkboxes underneath it.

  4. Click OK and you're done.

Visit the Microsoft Web site for a more in depth explanation (

The autoenrollment feature should add a little bit of extra system access security. If you choose not to use it, you have to delete all user accounts from the system manually. Also, remember that loose certificates sitting on compromised machines, stolen laptops or other errant equipment, can be exploited by users whose accounts may be gone, but whose ghosts aren't.

This was last published in February 2009

Dig Deeper on Microsoft identity and access management

Start the conversation

Send me notifications when other members comment.

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Please create a username to comment.