---
title: "MS CA Agent Overview & Prerequisites"
slug: "ms-ca-agent-overview"
updated: 2025-11-24T11:59:18Z
published: 2025-11-24T11:59:18Z
canonical: "docs.axiad.com/ms-ca-agent-overview"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.axiad.com/llms.txt
> Use this file to discover all available pages before exploring further.

# MS CA Agent Overview & Prerequisites

## Overview

The MS CA Agent allows UCMS to securely connect to an existing Enterprise CA registered in Active Directory, and request x.509 certificates on behalf of users.

Connection between the agent and UCMS is done over TLS, protected with mutual TLS authentication. The agent itself then communicates to the Microsoft CA over DCOM/RPC.

> [!WARNING]
> Warning
> 
> Axiad advises against exposing your PKI to the internet and recommends using an IPSec VPN to maintain security.
> 
> 
> 
> If you wish to configure it differently, then Axiad can help you find a solution, but you accept that there is additional risk.
> 
> 
> 
> Please reach out to [**customer success**](mailto:customer.success@axiad.com) if you have any questions about this or any other Axiad feature.

## System Requirements

### Minimum Hardware Requirements

Refer to Microsoft [Hardware requirements for Windows Server](https://learn.microsoft.com/en-us/windows-server/get-started/hardware-requirements?tabs=cpu&amp;pivots=windows-server-2025)

### Minimum Software Requirements

- **Operating system:** Windows Server 2019/2022/2025:
- **Features:**
  - .Net Framework: 4.5.1
  - minimum IIS (Internet Information Services) Web Server
