Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

To make eligible users or computers re-enroll from a Microsoft Active Directory Certificate Services (AD CS) template, open certtmpl.msc, right-click the template, choose Reenroll All Certificate Holders, and confirm that its major version increases. After Active Directory replication and Group Policy have caught up, trigger autoenrollment on a test client with gpupdate /force and certutil -pulse.

This is a template-specific trigger for certificates managed through AD CS autoenrollment. It does not contact every client, issue certificates by itself, revoke old certificates, or affect certificates issued by other templates or managed through systems such as Intune, SCEP, ACME, or a third-party PKI.

What “Reenroll All Certificate Holders” does

The action changes the certificate template’s major version. At a subsequent autoenrollment evaluation, an eligible client can compare the template version associated with its existing certificate with the current version and treat the major-version change as a reason to request a replacement outside the ordinary renewal window. Microsoft-hosted guidance describes this version-trigger behavior; see Microsoft Q&A on re-enrollment and template versions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The action changes template state; the client performs the enrollment. The client still needs to read the updated template, apply the relevant autoenrollment policy, contact an issuing CA, pass authorization and template requirements, and install the issued certificate. A template edit by itself is not a reliable substitute for explicitly selecting Reenroll All Certificate Holders. Verify a major-version increase; a minor-version change alone may not prompt existing holders to re-enroll.

“All holders” means eligible holders of that particular template that can successfully process autoenrollment—not every certificate in the domain. The action does not repair replication, Group Policy, DNS, CA connectivity, permissions, or enrollment failures. It also does not automatically revoke or delete the previous certificate.

Check prerequisites before changing a production template

  • Use an Enterprise CA workflow. This procedure assumes an AD-integrated Enterprise CA and certificate templates. Standalone CA requests and manually submitted certificates follow different processes.
  • Confirm the exact template. Identify the issuing template from the certificate’s template information, the CA database, or the client store. Similar certificate names may correspond to different templates—for example, client authentication, server authentication, NPS, domain controller, Wi-Fi, or VPN certificates.
  • Confirm the template is published. The relevant issuing CA must be configured to issue the template. In the Certification Authority console, publishing is done through Certificate Templates > New > Certificate Template to Issue. See Microsoft’s template guidance for remote access and NPS.
  • Check permissions. The intended users, computers, or groups need Read, Enroll, and Autoenroll rights as appropriate. User certificates generally use user accounts or user groups; computer and server certificates use the relevant computer or server groups.
  • Check autoenrollment Group Policy. The applicable GPO must enable Certificate Services Client – Auto-Enrollment, including Renew expired certificates, update pending certificates, and remove revoked certificates and Update certificates that use certificate templates. See Microsoft’s PKI configuration and validation guidance.
  • Check directory and service health. Verify AD replication, GPO scope and inheritance, client access to a domain controller and CA, enrollment-policy connectivity, and CA availability. Identify a pilot group and the services that depend on the certificate before initiating a broad rollout.

Review template settings before triggering re-enrollment: validity and renewal periods, subject and SAN construction, intended purposes (EKUs), key-storage provider, key size, issuance requirements, compatibility, and permissions. Changes to subject names, EKUs, cryptographic settings, or private-key behavior can affect compatibility. For substantial changes, test a duplicated template and migrate deliberately; certificates associated with the old template do not automatically become certificates from the new template.

Force re-enrollment and verify the template version

  1. On an administrative system with the Certificate Templates snap-in available, run:
    certtmpl.msc
  2. Find the exact template used by the existing certificates. Right-click it and select Reenroll All Certificate Holders, then confirm.
  3. Refresh or reopen the template view and verify that the major version increased. Do not proceed on the assumption that the action worked if the major version has not changed. Check that you selected the intended template and that the console is showing current directory data.
  4. Allow the updated template information to replicate through Active Directory before expecting every client to see it. Administrators commonly use the following to investigate replication health:
    repadmin /replsummary
    repadmin /showrepl

    These are diagnostic examples, not proof that every domain controller has converged. Follow your organization’s replication-health process, especially if clients use different sites or domain controllers.

Trigger autoenrollment on a client

Start with a pilot client that is authorized for the template. In an elevated computer context, refresh policy and pulse the autoenrollment engine:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
gpupdate /force
certutil -pulse

For computer-context autoenrollment, Microsoft also documents:

Rank #3
Windows Server 2016 Security, Certificates, and Remote Access Cookbook: Recipe-based guide for security, networking and PKI in Windows Server 2016
  • Windows Server 2016 Security, Certificates, and Remote Access Cookbook: Recipe based guide for security, networking and PKI in Windows Server 2016
  • Packt Publishing
  • ABIS_BOOK
certreq.exe -autoenroll -q

For a user certificate, run the pulse in the relevant signed-in user’s context:

certutil -user -pulse

Computer and user enrollment are separate contexts: computer certificates are evaluated by the Local System account, while user certificates are evaluated for the signed-in user. Running a command in the wrong context can make it appear that nothing happened. Microsoft documents certutil -pulse as an autoenrollment trigger in its certutil command reference, and documents certreq.exe -autoenroll -q in its PKI validation guidance.

A pulse requests an evaluation; it does not guarantee issuance. Autoenrollment also runs during normal computer startup and Group Policy processing. Timing varies with policy, client state, connectivity, and enrollment requirements. A Microsoft key-based-renewal example describes an approximately eight-hour evaluation interval in that scenario, but that should not be treated as a universal timing guarantee.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Verify issuance, then verify service use

For a computer certificate, open certlm.msc and inspect Personal > Certificates. For a user certificate, open certmgr.msc. From a command prompt, the local computer’s Personal store can also be inspected with:

Best Value
ZPARIK 6 Pack Guest Checks Books, Server Note Pads, Pink
  • Standard size: 6 pink server note pads, Each Book Comes with 50 bound order slips - that's 300 ticket sheets total! Check Pads Size 6.75 x 3.5 inch.
  • Convenient Work: These guest check books for servers have a tear-free dotted line that is easy to rip off. You can give as a customer copy or keep for record keeping. We've provided extra rows on the back for additional note taking.Perfect For Restaurants, Lounges, Hotels, Cafes, And Waiters To Use.
  • Record Important Information: These server note pads can record important information.Each ticket has a unique serial number printed at the top, dates, order details, number of guests, order amount, table numbers etc. They are lightweight, small and can fit most aprons. They can be used on-demand and can help decrease errors in orders, while improving work efficiency.
  • High Quality: Sturdy, Not Drop Powder, It's Thick, You Can Write On The Back And Front Easily.Their whole page printing has clear handwriting and a reasonable layout. On the customer retention part of each guest check, "THANK YOU" on the back to make customers feel appreciated.
  • Contact Us: We're confident that the quality of the server note pads will go beyond your expectation. If you experience an issue, feel free to contact us, we'll appreciate it to learn from your experience, and we'll make it better
certutil.exe -q -store my
certutil.exe -q -v -store my

Compare the new certificate with the old one. Check its template, issuer and chain, subject and SAN, EKUs, validity dates, thumbprint, and private-key presence and accessibility. Confirm that it is the intended replacement and that it chains to the trust anchors clients and services actually use. Microsoft’s PKI validation guidance also describes certificate-store inspection.

Issuance is not the same as activation. Check the consuming service separately: an IIS binding, NPS/RADIUS configuration, VPN gateway, Wi-Fi supplicant, LDAPS endpoint, cluster, domain controller, IPsec policy, or application may select a certificate by thumbprint or need a binding update or restart. Some services select a suitable newer certificate automatically; others do not. Test the actual authentication or TLS path before treating the rollout as complete.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot clients that did not re-enroll

  1. Did the template’s major version change? If not, confirm the right-click action was completed on the correct template, refresh the console, and check whether the administrative system has current directory data. Editing a property or changing only a minor version may not be enough.
  2. Can the client see the updated template? Check AD replication and which domain controller the client is using. Different sites or domain controllers can temporarily present different data.
  3. Is the client evaluating the right certificate context? Confirm the certificate is from the changed template and that you triggered the user or computer context that owns it. Manually enrolled certificates may need a separate renewal process.
  4. Is policy applied and is the account authorized? Check the GPO’s scope, inheritance, and autoenrollment settings. Confirm the enrolling principal has Read, Enroll, and Autoenroll rights, and that group membership has replicated.
  5. Is the CA able to issue the template? Confirm publication on the relevant CA, network access to the CA and enrollment-policy services, and normal CA operation. A request may remain pending if manager approval is required; inspect the CA console, the client’s request store, and Certificate Services Client event logs.
  6. Can the client satisfy template requirements? Subject-name or SAN requirements, EKUs, key-provider settings, key-size requirements, or private-key permissions can prevent issuance for some machines even when others succeed.
  7. Was a certificate issued but not activated? Check the service’s configured thumbprint or selection behavior, private-key access, bindings, and restart requirements. Check every load-balanced or clustered node, not just one client.

gpupdate /force refreshes policy; it does not fix a broken PKI path or an authorization failure. For event details, review the client’s Certificate Services Client logs in Event Viewer, alongside CA request status and relevant server logs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Special cases that need a different plan

  • Manual enrollment: The template-version trigger is aimed at autoenrollment. A manually requested certificate may need to be renewed or replaced through its original enrollment process.
  • Intune, SCEP, PKCS, Cloud PKI, ACME, or another PKI: Changing an AD CS template generally does not change certificates managed through a separate profile, protocol, or certificate lifecycle service. Use that system’s renewal controls.
  • Duplicated template: A duplicate has a new template identity. Existing certificates tied to the original are not automatically treated as certificates issued from the duplicate. Publish and deploy the new template, grant permissions, and plan migration.
  • Key-based renewal: This is a distinct configuration and renewal pattern, not another name for the major-version trigger. It has specific template prerequisites, including settings for using subject information from an existing certificate. Microsoft’s key-based renewal guidance documents a manual test such as certreq -machine -q -enroll -cert <thumbprint> renew.
  • CA hierarchy or trust changes: Re-enrolling a leaf certificate does not by itself deploy a new root or intermediate, update CDP/AIA configuration, or complete a CA migration. Handle trust-store deployment, revocation publication, chain validation, and service cutover separately.
  • Urgent invalidation: Re-enrollment does not revoke the old certificate. If it is compromised or must be invalidated, revocation and CRL/OCSP publication are separate actions. Confirm clients can validate the replacement before relying on it.

Roll out safely at scale

A major-version change can prompt many clients to request certificates in a short period. That can increase CA and domain-controller load, create many new private keys, expose client or service compatibility problems, and concentrate future certificate expirations around the rollout date. For a large population:

  1. Record or export the current template configuration and document dependent services.
  2. Test the change with a lab client, then a small production pilot covering representative sites and device types.
  3. Capture old and new thumbprints; confirm certificate contents, private-key access, chain validation, and actual service use.
  4. Monitor CA request volume, pending requests, failures, and client enrollment events. Expand in waves if the pilot succeeds.
  5. Keep the old certificate until the replacement is proven and the service has cut over. Do not delete or revoke it merely because a new certificate appeared.

For the normal Windows-domain use case, AD CS templates and Group Policy are the native mechanism. A separate certificate-lifecycle platform may be relevant when an organization needs inventory, policy, and automation across multiple CAs, clouds, operating systems, appliances, or public-certificate providers; it is not required just to trigger re-enrollment from one AD CS template.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.