AD CS web enrollment: why HTTPS alone does not stop machine-account NTLM relay

HTTPS alone does not close AD CS machine-account NTLM relay exposure. Review enrollment endpoints, enforce EPA, remove unnecessary NTLM paths, and investigate issued certificates rather than treating a password reset as proof of containment.

Separate transport encryption from authentication protection

An HTTPS enrollment endpoint can remain exposed when it accepts NTLM without enforced Extended Protection for Authentication (EPA). Microsoft identifies this configuration as an ESC8 relay risk and recommends enabling EPA alongside disabling HTTP. HTTPS protects transport; channel binding addresses the relationship between authentication and the protected channel. RFC 5929 defines TLS channel-binding types, including one based on the server certificate’s hash. The practical distinction is important: confirming HTTPS availability is not equivalent to confirming that IIS enforces authentication protection.

The attack chain starts before enrollment. MITRE documents forced authentication, including EFSRPC abuse that causes a computer to authenticate to another system. CISA describes attackers relaying that authentication to AD CS web enrollment and obtaining a certificate for the server’s account. It documents subsequent certificate-based AD authentication to obtain a Kerberos ticket-granting ticket. This is the certificate-to-Kerberos consequence relevant to PKINIT. Success remains conditional: the evidence does not establish that every enrollment endpoint issues a usable certificate or that every relay compromises a domain.

Evidence: Forced Authentication, Security assessment: Certificates, Channel Bindings for TLS, NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations, KB5005413: Mitigating NTLM Relay Attacks on Active Directory Certificate Services (AD CS)

Inventory endpoints before inspecting IIS

Begin with a recommended inventory of Certificate Authority Web Enrollment, also called Certsrv, and Certificate Enrollment Web Service, abbreviated CES. Record each hosting server, enrollment application, responsible owner, business dependency, permitted transport, and authentication configuration. Include services retained for compatibility, not just those used by current deployment workflows. Microsoft explicitly identifies both enrollment services as potentially affected. Ask owners whether each endpoint remains necessary before deciding whether to harden it or retire it; an undocumented dependency deserves investigation, not an assumed exception.

Next, inspect Windows Authentication providers and the EPA setting on every inventoried IIS enrollment application. Record whether NTLM remains accepted, whether EPA is enforced, and whether Require SSL is enabled. These are recommended review checks, not an assertion that installing AD CS supplies secure settings automatically. Defender for Identity’s ESC8 assessment can identify problematic endpoints, but requires a sensor installed on an AD CS server. Impacted entities update within minutes, while scores and statuses update every 24 hours; dashboard completion is not immediate validation.

Evidence: Security assessment: Certificates, KB5005413: Mitigating NTLM Relay Attacks on Active Directory Certificate Services (AD CS)

Enforce EPA and reduce enrollment dependencies

For retained services, follow Microsoft’s primary mitigation: enable EPA and disable HTTP by enabling Require SSL. Microsoft recommends Required as the more secure EPA option. CES also needs its role-created Web.config updated; setting EPA only in the IIS interface is not the complete documented procedure. The extendedProtectionPolicy value Always corresponds to Required, while WhenSupported corresponds to the alternative supported setting. Restart IIS after the changes. Plan the maintenance window carefully: Microsoft states that the restart command stops and restarts all running IIS services.

Then reduce NTLM wherever compatibility permits. Microsoft lists domain-level NTLM restriction, incoming NTLM restriction on AD CS servers, and IIS restriction as additional mitigations, ordered from more secure to less secure. For IIS enrollment services, its documented provider setting is Negotiate:Kerberos. Treat broader policies and any exceptions as controlled changes requiring dependency testing, not interchangeable switches. Recommend disabling unnecessary enrollment services entirely, consistent with CISA’s advice to disable unused services. Neither retirement of one endpoint nor an NTLM exception should substitute for reviewing the remaining enrollment paths.

Evidence: NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations, KB5005413: Mitigating NTLM Relay Attacks on Active Directory Certificate Services (AD CS)

Validate the boundary and investigate certificate outcomes

Validate changes in a controlled environment before production, as Microsoft recommends. A useful review sequence is to confirm legitimate enrollment, check the effective authentication and EPA configuration, verify HTTP is unavailable, and document exceptions. Separately inspect RPC enrollment: Microsoft classifies missing packet privacy there as ESC11, not ESC8. The IF_ENFORCEENCRYPTICERTREQUEST flag is enabled by default and requires signed, encrypted RPC packets when enabled. Reviewing HTTPS and EPA on IIS does not replace checking that separate interface or investigating why its protection was disabled.

For incident response, do not use a machine-account password reset as the closure criterion. CISA’s documented outcome includes an issued certificate and potentially a Kerberos TGT, rather than merely disclosure of a password. Neither cited Microsoft relay guidance nor the CISA advisory states that a password reset invalidates those artifacts. Recommend investigating certificates issued for the affected account and subsequent certificate-based authentication, then establishing whether resulting access has been contained. Endpoint remediation reduces future relay exposure; it is not evidence that previously obtained access has ended.

Evidence: Security assessment: Certificates, NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations, KB5005413: Mitigating NTLM Relay Attacks on Active Directory Certificate Services (AD CS)

Sources and further reading

  1. Forced Authentication
  2. Security assessment: Certificates
  3. Channel Bindings for TLS
  4. NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations
  5. KB5005413: Mitigating NTLM Relay Attacks on Active Directory Certificate Services (AD CS)
  6. CVE-2023-23397 · Microsoft Office Outlook Privilege Escalation Vulnerability
  7. Identity infrastructure exposed to the internet: SMB file sharing (port 445)

Source links support the documented product behaviour. Recommendations and labelled examples are editorial guidance.