Photo by Wade Lambert / Unsplash

Mitigate PetitPotam in Active Directory Certificate Services

Jul 25, 2021
💡
Please refer to the links at the bottom of this article for the most up-to-date links by Microsoft.

Uninstall ADCS web enrollment

A quick method is to uninstall the ADCS web enrollment (reboot required). After this, you can’t use https://yourserver.domain.com/certsrv

Uninstall-WindowsFeature ADCS-WebEnrollment

Then disable the web server IIS (check before if any websites/services rely on):

Uninstall-WindowsFeature Web-Server

Official mitigations by Microsoft

Tags

Bastien Perez

Freelance Microsoft 365 - Active Directory - Modern Workplace