Latest / The Windows Podcast with Fexingo: Microsoft, PC, and Enterprise Windows Conversations / Windows 11 Is Killing Enterprise Certificate Auto-Enrollment
Transcript
- Lucas: Luna, have you dealt with a certificate renewal panic in the last six months? The kind where suddenly no one can connect to the corporate Wi-Fi or the VPN, and it's because the device certificate expired and Windows didn't auto-renew. Luna: Yeah, actually. Our IT team had that exact issue back in April. We thought it was a network outage, but it turned out to be certificates. What's going on? Lucas: Well, Microsoft quietly deprecated the classic Certificate Auto-Enrollment protocol in Windows 11. If you are still relying on Group Policy to push out certificates — and a lot of enterprises are — that pipeline is essentially shut off in the latest Windows 11 feature update, version 24H2. Luna: Wait, 'deprecated' as in 'still works but don't rely on it', or 'it's broken right now'? Lucas: In practice, it's broken. Microsoft officially deprecated the old Certificate Auto-Enrollment client-side extension in Group Policy back in 2023, but they kept it limping along. With 24H2, the extension is no longer installed by default. If your devices upgrade, that auto-enrollment simply stops. No renewal, no warning — just expired certificates. Luna: That's brutal. So what's the replacement? Intune, I assume? Lucas: Exactly. Microsoft wants everyone on Intune or Entra ID certificate-based enrollment. The Intune Certificate Connector, the SCEP certificate profile, or the newer PKCS certificate profiles. All cloud-managed. No more on-premises certificate authority auto-enrollment via Group Policy. Luna: But a lot of mid-sized companies still run their own on-premises Active Directory Certificate Services. They have a root CA, they issue certificates internally. That whole setup doesn't talk to Intune natively, does it? Lucas: It can, but not out of the box. You need the Intune Certificate Connector installed on a Windows server on-premises, which talks to your CA and then to Intune. It's an extra piece of middleware. And Microsoft has already deprecated version one of that connector. Version two is now in preview, but it's not widely deployed yet. Luna: So even if you want to stay hybrid, you're on a moving platform. Microsoft is essentially forcing a cloud-first architecture for certificate management. Lucas: Right. And the stated reason is security. The old auto-enrollment protocol had known weaknesses — it didn't support modern key storage, it relied on weaker cryptographic algorithms, and it was harder to audit. Microsoft's argument is that Intune-based enrollment gives you better security with tpm backed keys, device compliance checks, and centralized reporting. Luna: I get that. But the migration cost is real. I spoke to an IT director at a regional healthcare system — they have about 4,000 Windows devices, mostly laptops used by clinicians. Their entire Wi-Fi authentication is built on device certificates auto-enrolled via Group Policy. When they tested the 24H2 upgrade on a pilot group, every single device lost Wi-Fi connectivity within 24 hours because the certificate didn't renew. Lucas: That's exactly the scenario I'm hearing about. And healthcare is especially sensitive because you have strict compliance timelines — HIPAA, patient data, access controls. You can't have a week of network downtime while you reconfigure your PKI. Luna: Their solution was to postpone the 24H2 upgrade across the fleet and scramble to set up the Intune Certificate Connector. But that took them about three weeks to get fully tested and deployed. And they had to retrain their help desk on the new enrollment workflows. Lucas: That three-week delay actually sounds optimistic. I've heard of organizations that took two months because they also had to update their certificate templates, move to a more modern CA, and deal with the fact that some legacy applications require specific certificate attributes that Intune doesn't easily support. Luna: What about smart cards? A lot of enterprises still use smart cards for physical access and Windows login. Does the deprecation affect those? Lucas: It does. Smart card certificates are often enrolled via the same auto-enrollment mechanism. If that breaks, users can't authenticate to the domain, can't unlock their workstations. I've seen reports of federal contractors being hit hard by this because they rely on CAC cards — Common Access Cards — which use certificate-based authentication via auto-enrollment. Luna: So this is not just a 'convenience' issue. This is about core authentication infrastructure. Lucas: Exactly. And Microsoft's timeline is aggressive. Windows 11 24H2 is currently rolling out to commercial devices gradually, but it will become mandatory eventually. If you haven't migrated your certificate management by then, you'll have a fleet of devices that can't renew their certificates. Luna: Speaking of things that are useful — if this conversation is saving you from a potential certificate-related fire drill, here's a thought. The reason we can dig into stuff like this without it being buried under sponsor messages is that listeners like you help keep it ad-free. You can toss a coffee's worth of support at buy me a coffee dot com slash fexingo. That genuinely helps us keep doing deep dives on exactly this kind of thing. Lucas: Yeah, and we really appreciate that. It's what lets us spend the time to track down the real-world impact, like that healthcare system example. So thank you. Luna: Alright, back to it. Lucas, what about the alternative — using third-party certificate management tools? Are there options outside of Microsoft's stack? Lucas: Absolutely. Companies like Keyfactor, AppViewX, and Venafi all offer solutions that can handle certificate auto-enrollment on Windows 11 without relying on the deprecated Group Policy method. They typically use agent-based or api based approaches to enroll and renew certificates from any CA, including legacy on-premises CAs. Luna: And those work with 24H2? Lucas: Yes, because they don't rely on the deprecated Group Policy client-side extension. They install their own agent that handles the enrollment lifecycle independently. So if you're not ready to move to Intune but need to keep devices on the latest Windows 11, a third-party tool could be a bridge. Luna: But that's an additional cost. For a company that's already paying for Microsoft E3 or E5 licenses, Intune is included. A third-party tool is a separate line item. Lucas: Right. But the total cost of ownership might still be lower than the operational overhead of migrating to Intune if you have a complex PKI. I've seen estimates that migrating a typical 10,000-device environment to Intune certificate enrollment can take six months and cost hundreds of thousands in IT labor. A third-party tool might let you defer that migration while maintaining security. Luna: Interesting. So the decision really comes down to your timeline and your PKI complexity. If you have a simple setup with a single CA and a handful of certificate templates, Intune migration might be straightforward. If you have a forest of CAs, cross-forest trusts, and custom certificate policies, third-party might be more practical. Lucas: Exactly. And one more thing — Microsoft is also deprecating the legacy Certificate Services web enrollment pages. Those are the web interfaces that allowed users to request certificates manually via a browser. That's another pillar of the old PKI infrastructure that's going away. Luna: So the message is clear: on-premises certificate management is on life support. Microsoft wants everyone on cloud-first enrollment. Lucas: And that's part of a larger pattern. We've seen them push the same message for identity — moving from Active Directory to Entra ID. For device management — from SCCM to Intune. Now certificates. It's all part of the same modernization drive. Luna: But not every enterprise can move that fast. Especially regulated industries where change management is slow and audits are frequent. Lucas: Which is why we're talking about it now. If you're an IT admin listening, the takeaway is: test Windows 11 24H2 on a pilot group right now, check if your certificate auto-enrollment still works, and start planning your migration — whether that's to Intune, Entra ID, or a third-party tool. Don't wait until the upgrade wave hits you. Luna: Good advice. And maybe check if your certificate templates are using the latest cryptographic standards — that'll make any migration smoother. Lucas: Absolutely. On that note, I think we've given everyone something to look into. Thanks for listening, and we'll catch you next time on The Windows Podcast with Fexingo.