Certificate monitoring

Aswin Thomas(UST,IN) 426 Reputation points
2024-02-23T09:56:38.5633333+00:00

Hello Team.

Is it possible via SCOM 2019 to do the following from a certificate monitoring perspective.

*   Restrict access to certificate templates that allow server authentication, and monitor the enrollment of templates to ensure that they are not requested for external URLs.

  *   Monitor the certificate store on the Azure AD Connect server to ensure that it contains only trusted Root CAs.

Regards, Aswin

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,441 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. XinGuo-MSFT 15,781 Reputation points
    2024-02-26T08:58:40.96+00:00

    Hi,

    #1

    SCOM 2019 itself does not directly manage certificate templates or their permissions. In ADCS, you can restrict access to certificate templates by modifying the security permissions on the certificate templates.

    #2

    The Management Pack for Certificate Monitoring in SCOM 2019 can be used to monitor the certificate store on the Azure AD Connect server.

    0 comments No comments