Guide

On-Prem

The on-premises domain covers the infrastructure that stays in your own racks and stays yours to design, operate and answer for. It opens with the private certificate authority: the hierarchy and the decisions inside it that are permanent from the first signature, the revocation plumbing that has to stay reachable long after the servers that published it are forgotten, the templates that decide who gets to be trusted, and the maintenance calendar that keeps all of it alive.

PKI

19 articles
P 1Start here
Anchor

Why You Still Run a Private CA, and What Two Tiers Actually Buy

A private PKI is an authority structure, not a server role, and a short list of its decisions are permanent from the moment the first certificate is signed. Here is what a two-tier hierarchy actually buys, what an offline root does not buy, and why AD CS is not going anywhere in 2026.

P 2
Doctrine

The Offline Root: Designing for a Machine That Is Almost Never On

A root certificate authority spends its life switched off, which sounds like the end of its operational story and is actually the whole of it. What offline really means, why the root leaves the domain, and why its revocation list is the only deadline in your PKI that can take the estate down.

P 2.1
Build sheet

Build Sheet: The Offline Root CA

By the end of this you have a standalone offline root certificate authority built, its policy file and distribution points fixed before anything is signed, its first revocation list published with a year of margin, and its certificate and CRL exported ready for the web servers.

P 3
Doctrine

Revocation Is a Distribution Problem

The signing service can be offline for a week and nobody notices. Let the revocation list become unreachable and authentication fails across the estate for certificates that are perfectly valid. Why the distribution layer is the only part of a PKI that must be highly available, and how to build it so it is.

P 3.1
Build sheet

Build Sheet: Redundant CRL and AIA Web Servers

By the end of this you have two web servers behind one name serving your root CA certificate and revocation list over HTTP, with the issuing CA able to publish to both directly and no replication technology between them. This is the article that makes the URLs the root recorded real.

P 4
Doctrine

The Issuing CA: What Enterprise Integration Buys and What It Costs

The issuing authority is the machine that does all the work and carries all the risk. What Active Directory integration actually gives you, why a default installation can issue certificates the moment the service starts, and why the certificate it holds quietly shortens everything it signs.

P 4.1
Build sheet

Build Sheet: The Issuing CA, End to End

By the end of this you have an enterprise issuing CA signed by the offline root, publishing its revocation list to both web servers on its own schedule, validating clean in the enterprise PKI view, and deliberately unable to issue a single certificate until you design its templates.

P 5
Doctrine

Templates and the Discipline of Issuance

A certificate template is a standing grant, not a form. Why cloning is mandatory rather than tidy, why supply-in-request is not the villain people think it is, and why one template setting quietly stopped working for domain authentication when strong mapping enforcement completed.

P 5.1
Build sheet

Build Sheet: The Template Set, Autoenrollment, and Manual Enrollment

By the end of this you have five certificate templates cloned, scoped and published, automatic enrolment working for machines, users and domain controllers, and a manual path for web server certificates. This is the article where the authority issues its first certificate.

P 6
Doctrine

Operating a PKI: Trust, Backup, and the Calendar

A private PKI is not a system you run. It is a small number of dated obligations, two of which will take the estate down if missed, and a set of artefacts that have to survive the loss of the machines holding them. The operations article nobody writes.

P 6.1
Build sheet

Build Sheet: Trust Distribution, Backup, and the Maintenance Calendar

By the end of this you have trust distributed to domain members and a documented path for everything else, three-layer backups of both authorities stored off the machines that made them, a rehearsed annual root CRL procedure, and a one-page calendar somebody else can act on.

P 6.2
Build sheet

Build Sheet: Renewing the Issuing CA, and the Root

The operations article says a private PKI is two dates. One of them has a rehearsed procedure and the other has had none until now. Renewing a certificate authority at half its life, what changes in the published files when you do, and the one failure that hits software-key hierarchies specifically.

P 7
Doctrine

Where the On-Prem Estate Meets Cloud PKI

Everyone wants to know whether Intune Cloud PKI lets them delete the hierarchy they just built. It deletes NDES. It does not delete the PKI, and if you anchor it to your own root you have just made your annual revocation appointment matter to every managed device you own.

P 7.1
Build sheet

Build Sheet: Signing the Cloud PKI CSR

By the end of this you have a cloud issuing CA anchored to your own hierarchy, trust and SCEP profiles delivered to managed devices, and the subordinate CA template removed again. Plus the step people skip, which fails on the devices you did not test.

P 8
Doctrine

Post-Quantum Signing in AD CS: What ML-DSA Changes and What It Does Not

Your certificate authority can sign with a post-quantum algorithm now. That is a real capability and it is not a migration you can perform, because an authority cannot be converted in place. Here is what ML-DSA actually protects, what it costs in bytes, and why the work is trust distribution rather than cryptography.

P 9
Doctrine

A Second Issuing CA: When It Is Availability, When It Is a Boundary, and When It Is Neither

Two very different requests arrive wearing the same words. One of them wants a clustered authority and the other wants a second one, and they are not interchangeable. What a second issuing CA actually buys, why you cannot steer enrolment between two of them, and the control point almost nobody uses.

P 10
Doctrine

Private PKI and the Public Web PKI Are Different Systems

Public certificate lifetimes are collapsing toward 47 days and the question arrives every week: does this mean our certificate authority has to reissue everything monthly. It does not, and the test for which certificates are affected is not the one most people apply.

P 11
Doctrine

Retiring a Certificate Authority Without Taking the Estate With It

Uninstalling the role is the fifth of nine steps and the least consequential one. The dangerous part is that certificates outlive the authority that signed them, the directory objects outlive the uninstall on purpose, and the documented procedure is written in an order that will take you down if you follow it literally.

P 11.1
Build sheet

Build Sheet: Decommissioning an Enterprise CA

By the end of this you have an inventory of everything the old authority issued, its replacements deployed, its ability to authenticate removed, its objects out of the directory, its key accounted for, and a document saying when its revocation list can finally stop. In the order that does not break anything.

AD to Azure

12 articles
AD 1Start here
Anchor

Zero On-Prem AD: The Path, and What It Actually Takes

A 140-seat company with healthy hybrid AD, Intune, and Exchange Online can retire its last domain controller. The whole path in seven pausable stages, what it costs at Business Premium, and who should not attempt it.

AD 2
Doctrine

What Is Actually Pinning Your Domain

Every failed AD migration starts with a dependency list built from memory. The domain controllers have been keeping their own inventory for years. Stage 0 is learning to read it: what can pin a domain, the instrument for each class, and the gate that ends the guessing.

AD 2.1
Build sheet

Build Sheet: The AD Dependency Inventory

Turn on the instruments, run them for thirty days, and end Stage 0 with a dependency inventory that has zero unknowns: NTLM and LDAP auditing, the Kerberos consumer census, the account sweep, and the planted test that proves your silence is real.

AD 2.2
Build sheet

The Census, Automated

Nobody wants to read domain controller logs for a month by hand. Invoke-ADPinCensus turns on the instruments, collects across the window, and hands back one dependency report with the rows pre-populated and the dispositions left to you. What it does, what it deliberately does not, and how to run it.

AD 3
Doctrine

Identity: Cutting the Sync

Stage 1 is the one-way door. Converting synced users to cloud-managed is now a supported, reversible, per-user operation, which means you can rehearse the irreversible step on three people before you commit a hundred and forty. What changes, what lingers, and the version cliff the sync engine has waiting for you.

AD 3.1
Build sheet

Build Sheet: Converting to Cloud-Only and Disabling Directory Synchronization

The pilot-wave method for the one-way door: transfer a handful of users to cloud-managed, verify, then cut the sync for the tenant and clean up what lingers. Rollback shown where it genuinely exists, and the point of no return named plainly.

AD 4
Doctrine

Devices: The Rebuild You Were Hoping to Avoid

There is no supported way to convert a hybrid-joined laptop to Entra join without a reset, and Microsoft says so plainly. Stage 2 stops looking for the shortcut that does not exist and spends its effort making the rebuild cheap: what carries over, what does not, and the one thing you deploy before the first device moves.

AD 5
Doctrine

Replacing the Estate: Files, Print, Certificates, Wi-Fi

Stage 3 is where the services move. The file server becomes a set of destinations rather than a swap, print and certificates each get a directory-free replacement, and the Wi-Fi runs into the one gap Microsoft never filled. Mostly this article points at the series that already own the details.

AD 6
Doctrine

The Application That Will Not Move

Every zero-AD project meets one application that refuses to leave the directory. Stage 4 is a ladder you work down in order: replace it, re-authenticate it, isolate it, or keep a directory and admit what that costs. Microsoft's own migration guide is missing the rung that actually removes the dependency.

AD 7
Doctrine

What Your Domain Controllers Are Still Doing

Before you power anything off, one more census. The domain controllers carry quiet jobs that have nothing to do with logins: DNS, DHCP, time, the identity detection surface, the last stragglers still speaking old protocols. Stage 5 is the readiness check that stops a premature power-off.

AD 8
Doctrine

The Decommission

The last stage, and the one with a point of no return. An observation window and a scream test, the order of operations, the things that fail silently on their own schedule, and the go or no-go a consultant would actually sign. The build sheet handles the commands; this article handles the judgment.

AD 8.1
Build sheet

Build Sheet: Decommissioning the Domain

The pre-flight checks with their expected silence, the second controller then the last with the right flags, the insurance image, the tenant-side cleanup in order, and the stale-device sweep with the warning that saves a machine's recovery keys. The commands for the one stage that does not undo.