Some PDIs are currently unavailable, and PDI actions are paused. View the latest updates here. Read More

Certificate Management ADCS Integration -Access Denied during Get-WmiObject execution via MID Server

charushilam
Kilo Contributor

Hi Team,

We are implementing ServiceNow Certificate Management with Microsoft ADCS integration.

When a certificate request is approved, the certificate task fails with the following error:

Access denied
 
Stack Trace:
at System.Management.ThreadDispatch.Start()
at System.Management.ManagementScope.Initialize()
at System.Management.ManagementObjectSearcher.Initialize()
at System.Management.ManagementObjectSearcher.Get()
at Microsoft.PowerShell. Commands.GetWmiObjectCommand.BeginProcessing()

Environment:

  • ServiceNow Certificate Management
  • MID Server
  • Microsoft ADCS CA Server

What we have checked:

  • Certificate request and task are created successfully.
  • ECC Queue records are in Ready/Processed state; no ECC errors found.
  • MID Server is Up and Validated.
  • Error occurs after task approval during PowerShell execution.
  • The stack trace indicates failure while executing a WMI query (Get-WmiObject).

Questions:

  1. What permissions are required for the service account on the CA server?
  2. Does the service account require Local Administrator, Remote WMI, DCOM, and WinRM permissions?
  3. Has anyone encountered a similar "Access Denied" error during ADCS integration?
  4. Are there specific WMI namespaces or CA server permissions that must be configured?

Any guidance or troubleshooting suggestions would be appreciated.


Thanks,
Charushila Mahajan
0 REPLIES 0