2025 / Infrastructure / ADCS-PKI-001

2-Tier PKI Hierarchy with AD CS

Two-tier Microsoft AD CS PKI hierarchy for enterprise certificate issuance and operational control.

Purpose

Design and implement a two-tier PKI hierarchy that separates root trust from issuing certificate services.

Customer context

The customer needed certificate infrastructure for internal systems, device trust, and future security initiatives.

Scope

  • Offline root CA design
  • Enterprise issuing CA configuration
  • Certificate templates and enrollment permissions
  • Revocation publication planning
  • Backup and recovery procedure notes

Delivery approach

The PKI was built with a controlled ceremony for root material and clear documentation for day-two operations.

Outcome

The customer received a stronger certificate foundation with a documented hierarchy and operational ownership model.

Evidence of delivery

Build records, CA configuration exports, template inventory, and recovery notes were handed over.