If you’re trying to request a certificate from a non-domain joined computer using Certificates console (CertMgr.msc or CertLM.msc) then you need to install on the server that hosts your Certificate Authority the following components:
(maybe you need just one of them but I’ve installed both)
and then enter its URI in the following format:
https://dc.example.local/ADPolicyProvider_CEP_Kerberos/service.svc/CEP
That’s it, folks!
Also the following for username/password authentication:
https://<FQDN>/ADPolicyProvider_CEP_UsernamePassword/service.svc/CEP
Pingback: Windows Enterprise CA - Certificate Services - xandi's blog