JEA endpoint for Windows servers
certmon reads Windows servers over WinRM, restricted to this JEA endpoint: a connection can run exactly two read-only functions (Get-CertmonInventory: public certificates, service bindings, autoenrollment state; Get-CertmonVersion). Nothing on the server is changed.
- Create an AD group (e.g.
CONTOSO\certmon-Reader) containing the certmon server account (computer account or gMSA); restart the certmon service once. - On every server, as administrator:
& 'C:\Program Files\certmon\jea\Install-CertmonJea.ps1' -Account 'CONTOSO\certmon-Reader'(e.g. GPO startup script or software distribution; repeatable; WinRM must be running). - Check from the certmon server:
Test-CertmonJea.ps1 -ComputerName srv01.contoso.local(Restricted = True).
Member servers use a temporary virtual account (local administrator, limited to the two functions); domain controllers don't (it would be a Domain Admin) and run with the rights of the certmon account. Firewall: TCP 5985 or 5986 from the certmon server, plus the service ports for the TLS cross-check. Remove with Install-CertmonJea.ps1 -Uninstall.
More documents
Installation and setup
Requirements, firewall, service account, permissions, setup (also silent), initial setup, update, backup and troubleshooting.
Notifications
Alert logic, email over SMTP or Microsoft 365, Microsoft Teams and webhooks with an HMAC signature.
Findings
Every finding id with its meaning and severity: network scan, PKI and Windows servers.
Windows event log
Event ids of the certmon source for RMM and SIEM systems, with query examples.