question

VenkataChaitanyaRajuKonduru-4501 avatar image
0 Votes"
VenkataChaitanyaRajuKonduru-4501 asked VenkataChaitanyaRajuKonduru-4501 commented

Active Directory Certificate Services Disabled- Enterprise SubCA

Active Directory Certificate Services is getting disabled automatically on the SubCA which is in Azure. Any reason why that would happen?

There is no issue with CDP/AIA. Once the service is manually enabled, CA service runs without any issue. I have another SubCA in the same subnet and it doesn't have any issue like this.

Any leads in this regard would be appreciated. Thank you.


Regards,
Chaitanya.

windows-serverwindows-server-security
· 9
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

What do you mean "is getting disabled"? Can you provide more details (for example, a screenshot)?

0 Votes 0 ·

@Crypt32 Here you go. It's going into disabled in the StartUp type 99194-service.jpg



0 Votes 0 ·
service.jpg (209.4 KiB)
Crypt32 avatar image Crypt32 VenkataChaitanyaRajuKonduru-4501 ·

I would check for any 3rd part software that can do this. In addition, I would check all startup and autorun items for apps or scripts that can disable ADCS service.

0 Votes 0 ·
Show more comments

Hello @VenkataChaitanyaRajuKonduru-4501,
I am just writing to see if this question has any update. If anything is unclear, please feel free to let us know.
Thanks for your time.

Best Regards,
Daisy Zhou

============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.

0 Votes 0 ·

1 Answer

DaisyZhou-MSFT avatar image
0 Votes"
DaisyZhou-MSFT answered VenkataChaitanyaRajuKonduru-4501 commented

Hello @VenkataChaitanyaRajuKonduru-4501,

Thank you for posting here.

Hope the information provided by Crypt32 is helpful.


If now the issue still occurs. Can you start the AD CS service after it is disabled?

If so, you can start the AD CS service and check whether the service will be disabled again?

If the AD CS service is disabled at a specific time or regularly, you can grab Process Monitor to see if it helps when the problem occurs.

1.Download and install Process Monitor tool on the machine here.
https://docs.microsoft.com/en-us/sysinternals/downloads/procmon

2.Run Network Monitor as administrator.

3.Wait for the issue reproduces (remember/write the timestamp the issue reoccurs) and stop the trace after the AD CS is disabled.

4.Save the process monitor trace.

Note:
As private information and security information may be involved, the forum does not collect log information. Please try to view the saved logs yourself (look for processes or applications that may disable the service based on the point in time when the problem occurred).


Hope the information above is helpful.

Should you have any question or concern, please feel free to let us know.


Best Regards,
Daisy Zhou

============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@DaisyZhou-MSFT @Crypt32 The issue is resolved. We identified that there was a GPO that was disabling the ADCS and IIS service even after it was restarted. Thank you for your inputs.

Regards,
Chaitanya.




0 Votes 0 ·