Collection Rule for event with source CertificationAuthority and ID 39 Rule

  • ID:  Microsoft.Windows.CertificateServices.CARole.6.2.CertSvcEvents.39
  • Description:  Certificate Services did not start: DCOM registration
  • Target:  Certificate Service (2012)
  • Enabled:  On Essential Monitoring

Overridable Parameters

Parameter Name Default Value Description Override
Priority 2  
Severity 2  

Run As Profiles

Name
Default

Alert Details

Message Priority Severity
AD CS Access Control High Critical

Rule Knowledgebase

Summary

Certification authority (CA) access control permissions ensure that authorized components and users can complete required tasks. Access control errors can identify potential problems associated with insufficient or inappropriate use of permissions.

Causes
This rule does not contain any causes.
Resolutions

Correct DCOM registration errors

To perform this procedure, you must have membership in local Administrators, or you must have been delegated the appropriate authority.

To correct DCOM registration errors:

  • On the computer hosting the CA, click Start, point to Administrative Tools, and click Services.

  • Right-click Active Directory Certificate Services, and click Properties.

  • Click the Log On tab, and confirm that Local System account is selected.

  • If it is not selected, click Local System account, and then click OK.

  • Right-click the service and then click Restart

Caution: Because of the security requirements for the Active Directory Certificate Services (AD CS) service, logon accounts other than LOCAL_SYSTEM are not supported.

External References
This rule does not contain any external references.

See Also for Active Directory Certificate Services Management Pack


Downloads for Active Directory Certificate Services Management Pack

AZURE OPTIMIZATION ASSESSMENT GET STARTED
MIGRATION TO AZURE GET STARTED
SYSTEM CENTER MIGRATION TO AZURE GET STARTED
MIGRATION TO AZURE FOR SQL AND WINDOWS 2008 GET STARTED