![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
From any domain user account, open certlm.msc.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Certificates > Personal > Certificates > All Tasks > Request New Certificate.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Next.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Active Directory Enrollment > Client access.
Note: Do the following if you do not want to use Active Directory Enrollment options:
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Configured by You > Add New.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Enter the Enrollment Policy Server URI as CEP server address for either Username_Password or Kerberos Authentication.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Select Authentication type as Windows Integrated.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Validate Server.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
After successful validation, click Add.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Next.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Select any template.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Details > Properties.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Enroll.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
In the Subject tab, provide a fully qualified domain name (FQDN).
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
In the Private Key tab, select Make private key exportable.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Apply > Enroll.