> ## Documentation Index
> Fetch the complete documentation index at: https://docs.truu.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Enrollment Agent Computer Template

1. Open the Microsoft Management Console (MMC) and click **File** then click **Add/Remove Snap-in…** to add a new snap-in.

<img src="https://mintcdn.com/truu-2/m22YLP0oXSNG0U3O/images/docs/7ecd1c08cf9e5d97e4c6191aae7d9150d17188e9679c83747ac1b1ad202f8c42-image.png?fit=max&auto=format&n=m22YLP0oXSNG0U3O&q=85&s=a88055a5627ae6b29d4f93915c4ec897" alt="" width="2836" height="1450" data-path="images/docs/7ecd1c08cf9e5d97e4c6191aae7d9150d17188e9679c83747ac1b1ad202f8c42-image.png" />

2. Click **Certificate Templates,** then click **Add** and **OK**.

<img src="https://mintcdn.com/truu-2/rjjBxA7Z_Wk_-34G/images/docs/ece2adfe01e23ef48dcfe2f39a233166d33cad3d37a21e7c08cb60be25029d57-image.png?fit=max&auto=format&n=rjjBxA7Z_Wk_-34G&q=85&s=b5af1b9f1b5f443dfc22889e55127c6d" alt="" width="1684" height="1193" data-path="images/docs/ece2adfe01e23ef48dcfe2f39a233166d33cad3d37a21e7c08cb60be25029d57-image.png" />

3. Double-click on the **Certificate Templates** , then in the list of templates right-click on the **Enrollment Agent (Computer)** template and choose **Duplicate Template**.

<img src="https://mintcdn.com/truu-2/YlfY4z_3_-uDkBaP/images/docs/536be69bf1b2e5a32d86128db4e555f7bddd9607987e466664ad23b2be1ea873-image.png?fit=max&auto=format&n=YlfY4z_3_-uDkBaP&q=85&s=bd1b7e722f98d8437440ebf860cff82f" alt="" width="1024" height="443" data-path="images/docs/536be69bf1b2e5a32d86128db4e555f7bddd9607987e466664ad23b2be1ea873-image.png" />

  4. Navigate to the **Compatibility** tab. Ensure the operating system versions of the **Certificate Authority** and **Certificate recipient** are appropriately selected for your environment.

<img src="https://mintcdn.com/truu-2/ehCBQgFdl_pQd0MN/images/docs/abb835a8b0f4b14328328e5e0a6ab8ba72154d33b70c2b5a2fedb684f115ddc4-image.png?fit=max&auto=format&n=ehCBQgFdl_pQd0MN&q=85&s=267185ca1a122a013faf3d2252aab191" alt="" width="995" height="1391" data-path="images/docs/abb835a8b0f4b14328328e5e0a6ab8ba72154d33b70c2b5a2fedb684f115ddc4-image.png" />

5. Navigate to the **General** tab and provide a **Template display name:** for the template.  I.E TruUEnrollmentAgent(Computer).  

**NOTE: Do not leave any spaces in the name of the Template display name.  Also the Publish certificate in Active Directory is optional if your company policy doesn’t allow this. This will allow certificate info to be available in the AD object.**   

<img src="https://mintcdn.com/truu-2/jMF4bYA9yOA_2TKv/images/docs/387094d73f0d0fa234ae7d05a5f31e31631c834a685b349636ef11452da69466-image.png?fit=max&auto=format&n=jMF4bYA9yOA_2TKv&q=85&s=b202e3660004c025fe1eb47632191ca5" alt="" width="478" height="678" data-path="images/docs/387094d73f0d0fa234ae7d05a5f31e31631c834a685b349636ef11452da69466-image.png" />

6. Navigate to the **Cryptography** tab and set the following settings for **Key Storage Provider** (KSP) support:
   <img src="https://mintcdn.com/truu-2/YlfY4z_3_-uDkBaP/images/docs/69a4283e36b3140bf6df61797342b96f8b93f86fef844a3c05d3b830f1c9ff33-image.png?fit=max&auto=format&n=YlfY4z_3_-uDkBaP&q=85&s=be4d44ee77d6f01dcf923a5df7e2964f" alt="" width="390" height="555" data-path="images/docs/69a4283e36b3140bf6df61797342b96f8b93f86fef844a3c05d3b830f1c9ff33-image.png" />
7. In the **Request Handling** tab, select **Authorize additional service accounts to access the private key,** then add the **TruU service account** created for the CA Adapter service. Assign the TruU account **Read** permission, then click **Apply** to complete setup in this tab.
   <img src="https://mintcdn.com/truu-2/jMF4bYA9yOA_2TKv/images/docs/2fef298ed80febc8404c409922124eecc529f4307487ac0f8a2348023b0b4a3b-image.png?fit=max&auto=format&n=jMF4bYA9yOA_2TKv&q=85&s=db5b63dfb6003766b035f1f8cdfc0152" alt="" width="1874" height="1138" data-path="images/docs/2fef298ed80febc8404c409922124eecc529f4307487ac0f8a2348023b0b4a3b-image.png" />

  8. In the **Security** tab, add the **Server that the CA Adapter is installed on** with **Read** and **Enroll** permissions, and the **TruU service account** with **Read** and **Enroll** permissions. Click **Apply** to complete setup in this tab and then **OK**.   

<img src="https://mintcdn.com/truu-2/jMF4bYA9yOA_2TKv/images/docs/4559808c49968b6617b536f701f303c42e07cd6f54633b8faa7237bbeaeaecb5-image.png?fit=max&auto=format&n=jMF4bYA9yOA_2TKv&q=85&s=3d164d241421f2d1b6796fe048501ab2" alt="" width="681" height="488" data-path="images/docs/4559808c49968b6617b536f701f303c42e07cd6f54633b8faa7237bbeaeaecb5-image.png" />

9. Next, navigate to your **Certificate Authority,** then click the **Certificate Templates** folder. Right-click on the **folder** and choose **New** then, **Certificate Template to Issue**.   

<img src="https://mintcdn.com/truu-2/ehCBQgFdl_pQd0MN/images/docs/b44eeaef3931198ffeeaf596b507c4da6c52bdfc119b73ceb8b493f0b4655679-image.png?fit=max&auto=format&n=ehCBQgFdl_pQd0MN&q=85&s=1088285a9240e16fb2154d222f114c45" alt="" width="1872" height="1306" data-path="images/docs/b44eeaef3931198ffeeaf596b507c4da6c52bdfc119b73ceb8b493f0b4655679-image.png" />

10. Select the **TruUEnrollmentAgent(Computer)** template, then click **OK**.

<img src="https://mintcdn.com/truu-2/L38yxuvvUa8uAW5I/images/docs/08ea38b5e92059e97e142d5aee5f735809a19f95bfa1fab9c7f82bdf78448049-image.png?fit=max&auto=format&n=L38yxuvvUa8uAW5I&q=85&s=c31105b63c8312d61ab50ae4a796d910" alt="" width="1451" height="926" data-path="images/docs/08ea38b5e92059e97e142d5aee5f735809a19f95bfa1fab9c7f82bdf78448049-image.png" />

11. The new **TruUEnrollmentAgent(Computer)** template will appear in the list of **Certificate Templates**. Rightclick on the new **Enrollment Agent** template to verify its properties are set. Then, click **OK** to complete.

**Note:** The **Certificate Request Agent** intended purpose is configured for this certificate template only.

***

[Configure TruU CA Adapter with ADCS](/docs/untitled-page)

[Create the Smartcard Logon Template](/docs/create-the-smartcard-logon-template)
