---
title: "Configure the Key Recovery Agent Certificate Template"
slug: "key-escrow-for-a-microsoft-ca"
updated: 2023-07-21T21:05:06Z
published: 2023-07-21T21:05:06Z
canonical: "docs.axiad.com/key-escrow-for-a-microsoft-ca"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.axiad.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure the Key Recovery Agent Certificate Template

Key escrow is an arrangement in which the keys needed to decrypt encrypted data are held in escrow so that, under certain circumstances, an authorized third party may gain access to those keys. Configure your CA to enable key archival, then specify that your certificate templates have key archival enabled.

## Configure the Key Recovery Agent Certificate Template

1. Sign into a certificate authority as a domain administrator or a domain user.
2. Ensure that the domain user is a member of the **Domain Admins** or **Enterprise Admins Group,** and has the rights for **Issue and Manage Certificates**, **Manage CA**, and **Request Certificates for the CA**.  

  1. Right-click the CA.
  2. Click **Properties**.  
The **Properties** dialog box displays.
  3. Click the **Security** tab to view the user's privileges.  
![1key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/1key_escrow.png)
3. Open the **Server Manager.**
4. To create the Key Recovery Agent certificate template, from the menu, click **Tools > Certification Authority**.  
![2key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/2key_escrow.png)The **Certificate Authority** screen displays.
5. Right-click **Certificate Templates** and select **Manage** to see a list of certificate templates.
6. Right-click the **Key Recovery Agent** certificate template and select **Duplicate Template**.  
The Properties dialog box displays.
7. Click the **Compatibility** tab, and keep the default settings:  
![5key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/5key_escrow.png)
8. Click the **General** tab.
9. Provide a **Template display name** and select the **Validity Period** as required.  
![6key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/6key_escrow.png)
10. Click the **Cryptography** tab and keep the default settings:  
![7key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/7key_escrow.png)
11. Click the **Issuance Requirements** tab and uncheck **CA certificate manager approval**.  
![8key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/8key_escrow.png)NOTEBy default, this checkbox is enabled to ensure that the certificate request goes to the CA Pending Requests List. A CA admin would then need to approve the certificate issue manually, and you still would not be able to export the private key. To avoid this, you must uncheck this option so that you can export the private key of the Key Recovery Agent.
12. Click the **Security** tab and add the domain user who logged into the server.
13. Assign the domain user the **Read** and **Enroll** permissions.
14. Enable the **Read** permission to the **Authenticated Users**.  
![9key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/9key_escrow.png)
15. Click **Apply** and **OK** to save the template.
16. 1. Open the **Certification Authority snap-in**.
  2. Right-click **Certificate Templates**, and select **New** > **Certificate Templates to Issue**.  
![10key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/10key_escrow.png)
  3. Select the newly-created **Key Recovery Agent 2** certificate, and click **OK**.  
![11key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/11key_escrow.png)
17. 1. Using the **Run** window, open **certmgr.msc.**
  2. Right-click **Personal.**
  3. Click **All Tasks** > **Request New Certificate**.  
The **Certificate Enrollment** dialog box displays.  
**![13key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/13key_escrow.png)**
  4. Click **Next**.  
The **Certificate Enrollment Policy** screen displays.  
![14key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/14key_escrow.png)
  5. Click **Next**.
  6. Select the **Key Recovery Agent 2** certificate and click **Enroll**.  
![15key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/15key_escrow.png)
  7. Click **Finish** to complete the enrollment.  
![16key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/16key_escrow.png)
18. 1. Using the **Run** window, open **certmgr.msc.**
  2. Right-click **Personal > Certificates.**  
![17key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/17key_escrow.png)
  3. Right-click the CA**,** and click **Properties**.  
The **Properties** window displays.
  4. Click the **Recovery Agents** tab.
  5. Select **Archive the key** and enter a value for the **Number of recovery agents to use**.  
![18key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/18key_escrow.png)
  6. Click **Add** and select the issued certificate.  
![20key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/20key_escrow.png)
  7. Click **OK**<.
  8. Click **Apply**.
  9. Click **Yes** to restart the AD CS Service.
  10. Once the service is restarted, click **OK** in the **Properties** window.
  11. Right-click the CA and select **Properties**.
  12. Click the **Recovery Agents** tab to see the validated certificate.  
![21key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/21key_escrow.png)The Key Recovery Agent certificate template is now created and enrolled, and the CA is configured to use a Key Recovery Agent.
19. 1. Right-click the Key Management CA template and select Properties.  
The **Properties** dialog box displays.
  2. On the **Request Handling** tab, select the **Include symmetric algorithms allowed by the subject** and **Archive subject's encryption private key** options.
  3. If the Microsoft CA is integrated with HSM, configure the **Cryptography Provider Category**Key Management template.
    1. In the **Properties** dialog box, click the **Cryptography** tab .
    2. In the **Provider Category**, select **Legacy Cryptographic Service Provider**.![24key_escrow](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/24key_escrow.png)
    3. Click **Apply**, then **OK**.  
Your changes save.

The Key Recovery Agent private key is now available on the local machine certificate store where the web service is deployed.
