JEA endpoint for Windows servers

certmon reads Windows servers over WinRM, restricted to this JEA endpoint: a connection can run exactly two read-only functions (Get-CertmonInventory: public certificates, service bindings, autoenrollment state; Get-CertmonVersion). Nothing on the server is changed.

  1. Create an AD group (e.g. CONTOSO\certmon-Reader) containing the certmon server account (computer account or gMSA); restart the certmon service once.
  2. On every server, as administrator: & 'C:\Program Files\certmon\jea\Install-CertmonJea.ps1' -Account 'CONTOSO\certmon-Reader' (e.g. GPO startup script or software distribution; repeatable; WinRM must be running).
  3. Check from the certmon server: Test-CertmonJea.ps1 -ComputerName srv01.contoso.local (Restricted = True).

Member servers use a temporary virtual account (local administrator, limited to the two functions); domain controllers don't (it would be a Domain Admin) and run with the rights of the certmon account. Firewall: TCP 5985 or 5986 from the certmon server, plus the service ports for the TLS cross-check. Remove with Install-CertmonJea.ps1 -Uninstall.

More documents

  • Installation and setup

    Requirements, firewall, service account, permissions, setup (also silent), initial setup, update, backup and troubleshooting.

  • Notifications

    Alert logic, email over SMTP or Microsoft 365, Microsoft Teams and webhooks with an HMAC signature.

  • Findings

    Every finding id with its meaning and severity: network scan, PKI and Windows servers.

  • Windows event log

    Event ids of the certmon source for RMM and SIEM systems, with query examples.