WriteEnrollmentFlag
Summary
Description
Identification
PowerShell
Active Directory Module
.NET Directory Services
Active Directory Services Interface

Exploitation

Disabling Manager Approval on a Certificate Template using powershell
powershell
Request a Certificate After Manager Approval Is Disabled

Linux

Disabling Manager Approval on a Certificate Template using Certipy
CertipyRetrieve the current value of the msPKI-Enrollment-Flag attribute
Compute the new msPKI-Enrollment-Flag setting
Disable the Manager Approval Requirement

Request a Certificate After Manager Approval Is Disabled

Mitigation

Detection
Event ID
Description
Fields/Attributes
References
References
Last updated
Was this helpful?