Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

WSTEP and Windows Auto-Enrollment Explained

Windows Auto-Enrollment

WSTEP (WS-Trust X.509 Token Enrollment Extensions) is a Microsoft protocol that lets domain-joined and Azure AD/Entra ID-joined Windows devices automatically request and renew certificates from an internal CA, underpinning Windows auto-enrollment via Group Policy or Intune.

WSTEP is the protocol Windows devices use to enroll for certificates automatically, without a user manually requesting one. Domain-joined devices use Group Policy-driven auto-enrollment against Active Directory Certificate Services, while Entra ID-joined and MDM-managed devices use WSTEP through Intune’s certificate connector, both issuing certificates without end-user interaction.

Key Takeaways

  • WSTEP is built on WS-Trust, a broader web services security standard, specifically extended by Microsoft to handle X.509 certificate enrollment requests and responses.
  • Traditional Group Policy-based auto-enrollment applies to domain-joined devices and requires line of sight to an internal Active Directory Certificate Services CA.
  • Intune’s certificate connector uses WSTEP to extend auto-enrollment to Entra ID-joined and hybrid-joined devices that may never directly contact the internal CA.
  • Auto-enrollment via WSTEP typically issues certificates for machine authentication, user authentication, and specific application scenarios like Wi-Fi (802.1X) or VPN.
  • Certificate templates configured for auto-enrollment must have autoenrollment permissions explicitly granted, distinct from the standard enroll permission used for manual requests.

How Does Traditional Group Policy Auto-enrollment Work?

  1. An administrator configures a certificate template in AD CS with autoenrollment permissions granted to the relevant security group.
  2. A Group Policy Object enables auto-enrollment and links it to the organizational unit containing the target devices or users.
  3. At the next Group Policy refresh, the client checks which certificate templates it is permitted to auto-enroll for.
  4. The client generates a key pair and submits a certificate request using WSTEP, without any user prompt.
  5. The CA issues the certificate, and the client installs it automatically, repeating the check periodically to handle renewal ahead of expiration.

Enterprise PKI Services

Get complete end-to-end consultation support for all your PKI requirements!

How Does Intune Extend Auto-enrollment to Non-domain-joined Devices?

Devices that are Entra ID-joined or MDM-managed but never directly domain-joined cannot use traditional Group Policy-based auto-enrollment, since that mechanism depends on Group Policy processing against an on-premises domain controller. Intune’s certificate connector bridges this gap: it relays WSTEP enrollment requests from Intune-managed devices to an on-premises AD CS environment (or a cloud-based CA), letting those devices receive certificates through the same underlying protocol without ever joining the traditional domain.

What Permissions Does a Certificate Template Need For Auto-enrollment?

PermissionPurpose
ReadLets the client see that the template exists and is available
EnrollLets a user or device manually request a certificate from this template
AutoenrollLets a user or device receive a certificate from this template without a manual request, via Group Policy or Intune

All three permissions must be granted to the relevant security group for auto-enrollment to function; a template missing the Autoenroll permission will only support manual requests, even if Group Policy auto-enrollment is otherwise enabled.

What Commonly Breaks Windows Auto-enrollment?

  • Missing Autoenroll permission on the certificate template, the most common misconfiguration.
  • Group Policy not applying due to OU scoping or a disabled auto-enrollment policy setting.
  • Devices unable to reach the CA or Intune certificate connector due to network segmentation or an expired connector certificate.
  • Template version mismatches between what is published and what the client expects, especially after a template is edited.

How Encryption Consulting Helps

How Encryption Consulting Helps PKI-as-a-Service designs and troubleshoots Windows auto-enrollment deployments, including Intune certificate connector configurations, so device and user certificates issue reliably across both domain-joined and cloud-managed fleets. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.

Frequently Asked Questions

What is the difference between WSTEP and SCEP?

WSTEP is Microsoft’s protocol specifically for Windows auto-enrollment against Active Directory Certificate Services, typically for domain-joined or Intune-managed Windows devices. SCEP is a broader, vendor-neutral protocol used across MDM platforms and network devices, including non-Windows systems.

Does WSTEP work for non-Windows devices?

No, WSTEP is a Microsoft-specific protocol tied to Windows auto-enrollment and Active Directory Certificate Services. Non-Windows devices enrolled through Intune or other MDM platforms typically use SCEP or another cross-platform protocol instead.

Why isn’t my certificate template auto-enrolling?

The most common cause is a missing Autoenroll permission on the certificate template; Read and Enroll permissions alone are not sufficient. Group Policy scoping issues and connectivity problems to the CA or Intune certificate connector are the next most common causes.

Can Entra ID-joined devices use Windows auto-enrollment?

Yes, through Intune’s certificate connector, which relays WSTEP enrollment requests between Intune-managed devices and an on-premises or cloud-based CA, extending auto-enrollment to devices that are not traditionally domain-joined.

Get Windows Auto-Enrollment Working Reliably

Take the next step Encryption Consulting’s PKI Services team designs and troubleshoots Windows auto-enrollment, including Intune certificate connector deployments, so certificates issue without manual intervention. Explore PKI Services to get started.