Answered by:
SBS 2011: Network Device Enrollment Service missing from Active Directory Certificate Services

Question
-
I've just upgraded a SBS 2003 to SBS 2011, and now I need to enable Network Device Enrollment Service in Active Directory Certificate Services acc.to http://social.technet.microsoft.com/wiki/contents/articles/9063.network-device-enrollment-service-ndes-in-active-directory-certificate-services-ad-cs.aspx
But when I open Server Manager / Roles / Active Directory Certificate Services and click on Add Role Services acc.to Step 1 in above instructions then Network Device Enrollment Service isn't available.
Is this service not available for SBS 2011, or is it a package that needs to be installed separately ?
Regards
MWebjorn
- Edited by MWebjorn Tuesday, November 27, 2012 12:08 AM
Tuesday, November 27, 2012 12:07 AM
Answers
-
Ok, thanks Cliff. But then a message to Microsoft: It really sucks that you remove a feature from a product line without excplicitly pointing that out. Yes, it's only available on Windows 2008 R2 Enterprice, and SBS 2011 is based on 2008 R2 Standard. So how do I know that this feature has been removed which was present in previous versions ? I've searched your entire web for detailed SBS 2011 product info but just found some 10000ft marketing stuff. No exact description.
So SBS 2011 customers shouldn't be able to use other VPN technologies other than what Microsoft provides without functionality penalty ? This REALLY sucks !!!
MWebjorn
Wednesday, November 28, 2012 5:29 AM
All replies
-
Hi:
Apparently it is not available. Can you tell us what you are wanting to do by installing this service?
Larry Struckmeyer[SBS-MVP]
Tuesday, November 27, 2012 2:32 AM -
In the 2008 R2 product line, NDES is a feature of Enterprise and Datacenter editions. Standard and below do not have it, which includes SBS and Foundation. So this is not unique to SBS.
More info here:
Tuesday, November 27, 2012 4:11 AM -
I need it for my Cisco ASA5505 which runs L2TP VPN, and which needs SCEP/NDES to manage certificates. Is there some way to add this to SBS 2011 Standard ?
MWebjorn
Tuesday, November 27, 2012 10:46 AM -
No. As I linked to, it is *ONLY* a feature available in Windows 2008 R2 Enterprise. If you need this, you must add an OS with the appropriate feature and enable the role on THAT OS. That means 2008 R2 Enterprise, Datacenter, or 2012 Standard/Datacenter. I also feel it necessary to stress that this is NOT a restriction of SBS. Even someone who bought a stock-standard 2008 R2 Standard OS license would be unable to add/use this role's feature.
- Edited by Cliff Galiher Wednesday, November 28, 2012 12:49 AM
- Proposed as answer by Oscar Soto CL Tuesday, April 9, 2013 12:30 PM
Wednesday, November 28, 2012 12:48 AM -
Ok, thanks Cliff. But then a message to Microsoft: It really sucks that you remove a feature from a product line without excplicitly pointing that out. Yes, it's only available on Windows 2008 R2 Enterprice, and SBS 2011 is based on 2008 R2 Standard. So how do I know that this feature has been removed which was present in previous versions ? I've searched your entire web for detailed SBS 2011 product info but just found some 10000ft marketing stuff. No exact description.
So SBS 2011 customers shouldn't be able to use other VPN technologies other than what Microsoft provides without functionality penalty ? This REALLY sucks !!!
MWebjorn
Wednesday, November 28, 2012 5:29 AM