When integrating ADCS certificate templates into MDM to deploy user certificates to mobile devices, it is important to review the PKI deployment and certificate template permissions to ensure that certificates are issued only for authorized purposes and through authorized sources. The following steps will help validate that your existing ADCS certificate templates are securely configured.
Identify the Template Used by NDES
regedit.exe) and navigate to:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MSCEP
Open the Certificate Templates Console and Locate the Template
certsrv.msc).
Validate Security Permissions

Apply the Updated Permissions
Restart IIS to Apply Changes
For more information on securing NDES certificate templates, refer to the official Microsoft documentation .
After confirming that the NDES template is correctly configured and restricted, audit the Certification Authority to ensure certificates are issued only to the NDES service account.
Open the Certification Authority Console

Validate the Requester Account
For each certificate issued using the NDES template:

If certificates were requested by any users other than the intended NDES account, then the template permissions are overly permissive. Investigate and address immediately.
Revoke Unintended Certificates
If any unissued certificates are found:

This prevents unauthorized certificates from being used for authentication or enrollment.