Smart card logon does not work out of the box with Microsoft Active Directory. The PKI enablement of a Microsoft domain is performed in three main steps:
- Publication of necessary Certification Authority certificates to the domain.
- Availability of the Certificate Revocation Lists to the Domain Controllers and every machine on the network, servers included.
- Creation or verification of Kerberos authentication certificates for every DC in the domain.
Logon Process
Overall![]() | Machine and Domain Controller interaction![]() |

