Use an existing Microsoft certificate authority with SSLNexus certificate lifecycle management and customer-local deployment.
Use the configured AD CS connector and the template permitted for the requested certificate. The CA controls approval and template restrictions; SSLNexus does not override them.
AD CS requests can wait for approval. SSLNexus retains request identity and CSR state so polling and recovery do not depend on generating a replacement order after restart.
A licensed customer SSLNexus installation can carry out local deployment while communicating outbound with an MSP. Customer Relay remains request-only and does not provide the AD CS deployment lifecycle or Ansible/WinRM execution.
Start with one authorised target, test certificate acquisition and deployment, and confirm the resulting certificate is in use. Feature availability follows your installed release and active licence. The seven-day trial provides a way to evaluate the relevant workflow.