---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Microsoft CA certificates

# Microsoft Certificate Authority (CA) certificates discovery {#ariaid-title1}

* Release version: Yokohama
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

The ServiceNow Discovery application can discover Microsoft Certificate Authority (CA) certificates using the Microsoft CA - Certificate Management pattern. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.

## Request apps on the Store {#microsoft-ca-discovery__section_sv2_vw5_5mb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#microsoft-ca-discovery__inline-send-to-store}
Starting with version 1.27.0, Discovery and Service Mapping Patterns supports discovering the subject alternative name (SAN) for both the all request IDs and the template ID discovery methods.

## Prerequisites {#microsoft-ca-discovery__section_x4f_zrd_f4b}

Verify the following applications are up to date
:
    * Discovery and Service Mapping Patterns
    * CMDB CI Class Models
    {#microsoft-ca-discovery__ul_ys1_qwx_r2c}

Verify the certificate Authority process
:   Ensure that the CA process is up and running on the host machine.

Verify previous Windows discovery
:   Verify a Windows host was discovered during a previous horizontal discovery. For more information, see [Windows discovery](https://servicenow-prod.fluidtopics.net/f_Q~qP_q0vUp0GkIy~BTAQ "Discovery identifies and classifies information about Windows computers that use IPv4 addresses, IPv6 addresses, or both.").

Create a serverless discovery schedule

:   Create a discovery schedule to perform targeted discovery of Microsoft CA certificates using the host on which the CA process is running. For more information, see [Create a serverless schedule for Microsoft CA discovery](https://servicenow-prod.fluidtopics.net/buyGJZbVRv0APNc1dN5a1w "Create a serverless discovery schedule to discover Microsoft Certificate Authority (CA) certificates.").

## Data collected by Discovery during horizontal discovery {#microsoft-ca-discovery__section_t1y_mxd_f4b}

Discovery populates the data in the CMDB when running the Microsoft CA - Certificate Management pattern.  
{#microsoft-ca-discovery__table_xqd_syx_r2c__entry__2}

| Field | Description |
|-|-|
| Fingerprint \[fingerprint\] | Hash value of the certificate. |
| Fingerprint algorithm \[fingerprint_algorithm\] | Algorithm used to hash the certificate​. |
| Subject common name \[subject_common_name\] | Identifies the host name/domain associated with the certificate, listed in the certificate's Subject field. |
| Subject distinguished name \[subject_distinguished_name\] | Identifying information of the subject listed in the certificate's Subject field.​ |
| Issuer distinguished name \[issuer_distinguished_name\] | Distinguished name of the issuer​. |
| Comments \[comments\] | Includes a readable description for users. |
| Renewal tracking \[renewal_tracking\] | Indicates whether to create any priority 1 or priority 3 tasks for the expiring certificates.​ |
| Certificate Template \[cert_template\] | Certificate template that defines the policies and rules that a CA uses when a request for a certificate is received. |
| Certificate ThumbPrint \[thumb_print\]​ | Unique identifier for certificates in applications when making trust decisions, in configuration files, and when displayed in interfaces. |
| Issuer common name \[issuer_common_name\] | Common name of the issuer​. |
| Valid from \[valid_from\] | Validity start period of the certificate. |
| Serial Number \[serial_number\] | Serial number of the certificate. |
| Subject country \[subject_country\] | Two-letter country code in the certificate's Subject field. |
| Subject organization \[subject_organization\] | Organization listed in the certificate's Subject field. |
| Issuer \[issuer\] | Entity that signed and issued the certificate.​ |
| Subject organizational unit \[subject_organizational_unit\] | Organizational unit listed in the certificate's Subject field..​ |
| Subject alternative name \[subject_alternative_name\] | List of fully qualified domain names secured by the certificate​, listed in the certificate's Subject field. |
| Valid to \[valid_to\] | Validity end period of the certificate. |
| Name \[name\] | Name of the CI. |
| State \[state\] | Life-cycle state of the certificate​. For example: Installed, Issued, or Revoked. |
| Root issuer \[root_issuer\] | Root entity that signed and issued the immediate certificate. |
| Subject locality \[subject_locality\] | Locality listed in the certificate's Subject field. |
| Subject state \[subject_state\] | State listed in the certificate's Subject field. |
| Operational status \[operational_status\] | Indicates whether the certificate is valid or was revoked. Possible values are: * Operational: Valid certificate * Non-Operational: Revoked certificate {#microsoft-ca-discovery__ul_ts1_d2v_v2c} |
| Signature algorithm \[signature_algorithm\] | Signature algorithm of the certificate. For example: SHA-256, sha256RSA, or SHA1withRSA. |
| Request Type \[request_type\] | Format used for requesting the certificate. |
| Request Submission Date \[request_submission_date\] | Date that the certificate request was submitted. |
| Request Resolution Date \[request_resolution_date\] | Date that the certificate request was resolved by the CA. |
| Request Revocation Date \[request_revocation_date\] | Date that the certificate was revoked. This field is populated only for revoked certificates. |
| Effective Revocation Date \[effective_revocation_date\] | Date that the certificate was effectively revoked by being added to the Certificate Revocation List (CRL). This field is populated only for revoked certificates. |
| Revocation Reason \[revocation_reason\] | Reason for the certificate's revocation. This field is populated only for revoked certificates. |
| Requester Name \[requester_name\] | Name of the person who requested the certificate. |
| Template Enrollment Flags \[template_enrollment_flags\] | Information about the certificate that needs to be acted on by the CA or the certificate's owner. For more information, search for the error code in [the official Microsoft documentation site](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-crtd/ec71fd43-61c2-407b-83c9-b52272dec8a1). |
[Table 1. Unique Certificate \[cmdb_ci_certificate\]]

{#microsoft-ca-discovery__table_xqd_syx_r2c}

## CI relationships {#microsoft-ca-discovery__section_s3r_15ss_52b}

The Microsoft CA - Certificate Management pattern doesn't create any CI relationships.
* **[Create a serverless schedule for Microsoft CA discovery](https://servicenow-prod.fluidtopics.net/buyGJZbVRv0APNc1dN5a1w)**   
  Create a serverless discovery schedule to discover Microsoft Certificate Authority (CA) certificates.

