Skip to content Book a PKI health check Get incident support

Microsoft certificate services

ADCS deserves specialist attention.

It can issue the identity that unlocks your estate — and one weak template, unavailable revocation point or mishandled CA key can undermine the whole chain.

Request an ADCS audit

Why ADCS

The risk hides in combinations.

A template flag may be legitimate. A permission may be legitimate. Together, they can become a domain escalation path.

How a health check runs

Five steps. Two weeks.
No changes to production.

scoping — call notes
PS> Get-CAHierarchy -Summary

Forest            : corp.example.com
Enterprise CAs    : 3
  ROOT-CA-01      Offline  SHA256  RSA4096  exp 2039
  ISSUING-CA-01   Online   SHA256  RSA2048  exp 2031
  ISSUING-CA-02   Online   SHA1    RSA2048  exp 2029
Published templates : 41
Endpoints (est.)    : 5,000 – 15,000

# scope agreed. no credentials exchanged.

Representative output. Collection scripts are supplied for your review before anything runs.

Flagship engagement

Engagement record

We assess your CA hierarchy, certificate templates, permissions, revocation infrastructure and key protection against known attack paths and operational failure modes — then hand you a risk-ranked remediation roadmap your engineers can work straight from.

Format
Fixed, $6,000–$12,000 by environment size
Access
Read-only preferred. No changes to production.
Output
Risk-ranked report + remediation walkthrough
Typical
About two weeks from evidence collection

ADCS engagements

Start with the failure mode.
Choose the engagement second.

01

PKI / ADCS Health Check

Fixed-price assessment

We assess your CA hierarchy, certificate templates, permissions, revocation infrastructure and key protection against known attack paths and operational failure modes — then hand you a risk-ranked remediation roadmap your engineers can work straight from.

You receiveRisk-ranked findings, evidence appendix, remediation roadmap and engineer walkthrough.

02

Net-New Design & Deployment

Design and implementation project

A defensible hierarchy built around an offline root, resilient issuing tier, controlled templates, autoenrolment and durable revocation publishing.

You receiveArchitecture, build scripts, CP/CPS documentation, ceremony records and operational runbooks.

03

Migration & Upgrade

Scoped transformation

Modernise CA operating systems, keys, algorithms or hierarchy while preserving trust for the certificates and applications already in service.

You receiveDependency inventory, migration sequence, rollback gates, validation plan and handover.

04

Troubleshooting & Incident Support

Priority or planned support

Rapid diagnosis for failed autoenrolment, broken chains, revocation outages, template errors and suspected CA compromise.

You receiveIncident hypothesis, evidence-led diagnosis, safe recovery sequence and post-incident actions.

Common questions

Clear access.
Controlled collection.