This is a collection certreq commands. It might be of use for someone administrating an ADCS instance. Issuing a leaf certificate certreq -submit -attrib "CertificateTemplate:CertTemplateName" .\signing_request.csr Issuing an issuing CA certificate This assumes that the root CA is not running in enterprise CA mode. certreq -attrib "CertificateTemplate:SubCA" -attrib "ValidityPeriod:1" -attrib"ValidityPeriodUnits:Years" .\SSL_CERT_R.csr The certreq tool will then output a RequestId. Look this up in certsrv.msc and approve it. Or not.