Steps to manually install User certificates within Windows 10

What are the steps to manually install User certificates within Windows 10 that have been created by an internal Server 2016 certification authority?
IT GuyNetwork EngineerAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

JohnBusiness Consultant (Owner)Commented:
You would need to Manage Trusted Root Certificates so far as I know to do this.

What is missing that you need to do this?

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
IT GuyNetwork EngineerAuthor Commented:
I have some user certificates that are supposed to automatically install on all computers within my domain but the problem is so far they have only deployed on the Server 2016 domain controllers and haven't deployed on the Windows 10 domain-joined computers. So I'm trying to figure out if there is a way of me manually installing these.
JohnBusiness Consultant (Owner)Commented:
I think they must be added via the Manage Certificate approach.

We have not had to do this at this point.
JohnBusiness Consultant (Owner)Commented:
If you have the certificate file (have not done this in years), use MMC to install it.

Is the CA issuing the certificates a member if the domain? As suggested, is the CA's public certificate added as trusted in a GPO computer configuration, Windows settings, security settings, ........

The certificates are published in AD.
There should be a user/computer GPO with respective auto enroll rules while the CA ihas configured templates.

Does the CA reflect requested certificates in the pending folder awaiting approval, or the certificates are in the issued folder?
Mmc file, add/remove snapit certificate authority, or use the admin tools....... On the CA (rsat on the workstation)

Mmc, file add/remove snap-in certificates.

It shoukd gave your user certificate in the AD higherarchy.

Use a browser,


Go through the options to request a user certificate.
But before double check the CA as noted, whether it is configured to issue versus await approval.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows 10

From novice to tech pro — start learning today.