Validating MSCA using CEP/CES in Client Machine

  1. Login to an end machine using the service account created.
  2. Open a command prompt as administrator and run the gpupdate /force command to update the group policy.
  3. Go to MMC and add the user and machine certificate snap-ons.
  4. Right-click the personal store of User Certificates and click All-tasks > Request New Certificate.
    The CEP friendly name configured earlier will be shown there. Click that and proceed to enroll a certificate.
  5. Similarly test certificate enrollment for computer certificates.