Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error 0x80094800

Error 0x80094800: the CA does not support the requested certificate template

9 min read Updated October 4, 2026 Windows Server: AD, DNS & Group Policy

Fix it now

0x80094800 is CERTSRV_E_UNSUPPORTED_CERT_TYPE: the requested certificate template is not supported by this CA. Usually the template exists in Active Directory and was never published to this CA, which takes two minutes. The other cases are a template the CA cannot read, or one built for a newer CA than you are running.

Run these on the certification authority, in an elevated Command Prompt

certutil -CATemplates
certutil -SetCATemplates +WebServerV2
certutil -CATemplates
  1. Read the first certutil -CATemplates output. If the template is not listed, this CA is not configured to issue it and that is your answer.
  2. Publish it from the console if you prefer: in the Certification Authority console, right-click Certificate Templates, choose New, then Certificate Template to Issue, and select it.
  3. From the command line use certutil -SetCATemplates +<TemplateName> with the template’s internal name, not its display name.
  4. If the template does not appear in the list of templates you can add, open its Compatibility settings and compare the Certification Authority level with the CA you are running.
  5. Retry the request, then check the CA’s Failed Requests view if it still does not go through.

There is a third possibility that catches people out: if Authenticated Users has been removed from the template’s ACL, the CA itself can no longer read the template in Active Directory, and clients see exactly this code.

If the template now appears in the CA’s list and the request succeeds, stop here. The next section covers the two cases where publishing does not help.

Why it happens

An enterprise CA issues only the templates it has been configured to issue. The template object lives in Active Directory and is visible forest-wide, so a client can see and request a template that this particular CA has never been told about. What comes back is CERTSRV_E_UNSUPPORTED_CERT_TYPE, and on the CA the policy module records a denied request.

The second cause is a permissions problem wearing the wrong error message. Microsoft documents that removing the Authenticated Users group from a template’s access control list stops the enterprise CA reading that template in Active Directory – the CA object is itself covered by that group – and requests against the template then fail. The published fix is that every CA’s computer account must be added to the template ACL with Read. On the CA you also see a warning at service start saying the template could not be loaded.

The third cause is version. A template carries compatibility settings for the certification authority and for the certificate recipient, and a template built for a newer CA than you are running cannot be issued by it – the template will not even appear in the list of templates you can add. That is a capability boundary rather than a configuration one.

The template was never published to this CA

You have this one if certutil -CATemplates does not list it, and other templates issue normally.

  1. Publish it: certutil -SetCATemplates +<TemplateName>, or add it in the console under Certificate Templates, New, Certificate Template to Issue.
  2. Re-run certutil -CATemplates and confirm it appears.
  3. In a multi-CA environment, publish it on every CA that clients might reach, not just the one you tested.

The CA cannot read the template

You have this one if The template is published, and at service start the CA logs a warning that the template could not be loaded. Requests fail with this code.

  1. Open the template’s Security tab and check whether Authenticated Users is present.
  2. If it has been removed, add every CA’s computer account with Read – that is the published remedy.
  3. Restart Certificate Services and confirm the load warning has gone.

This is the cause that survives every attempt to re-publish the template, because publishing is not the thing that is broken.

The template is a newer version than the CA supports

You have this one if The template does not appear in the list of templates available to add, and its compatibility settings name a newer CA version.

  1. Open the template’s Compatibility tab and read the Certification Authority setting.
  2. Either lower the compatibility level – which loses the features that required it – or issue from a CA that supports it.
  3. Check the Certificate recipient setting at the same time, since a level higher than your clients support causes its own problems.

Replication has not caught up

You have this one if The template issues from one CA and not another, or from one site and not another, and nothing else differs.

  1. Confirm the template object exists on the domain controller that CA is using.
  2. Give replication time, or force it, before making changes that will need undoing.
  3. 0x80094813, CERTSRV_E_UNKNOWN_CERT_TYPE, is the code for templates to be enabled that could not be found at all – that one points at replication or a renamed template rather than publishing.

Full reference

The codes in this family

Code Constant Published meaning
0x80094800 CERTSRV_E_UNSUPPORTED_CERT_TYPE The requested certificate template is not supported by this CA
0x80094813 CERTSRV_E_UNKNOWN_CERT_TYPE One or more certificate templates to be enabled on this certification authority could not be found
0x80094801 CERTSRV_E_NO_CERT_TYPE The request contains no certificate template information
0x80094811 CERTSRV_E_KEY_LENGTH The public key does not meet the minimum size required by the specified certificate template

What the CA logs while the client sees the error

Event ID Source What it records
53 CertificationAuthority Active Directory Certificate Services denied the request, naming the request ID, the template and the error code behind the denial
77 CertificationAuthority The policy module warning that a named certificate template could not be loaded, logged when Certificate Services starts

Those two events split the diagnosis cleanly. A 53 with this code and no 77 means the template exists and is readable but is not published on this CA. A 77 at service start means the CA could not load the template at all, which is the Authenticated Users case.

Display name and internal name

certutil -SetCATemplates takes the template’s internal name, which is frequently not what the console shows. A template displayed as “Contoso Web Server (2019)” may have an internal name with no spaces at all. Read it from certutil -template output or from the template’s properties before scripting anything, because a mistyped name silently publishes nothing.

Requests that arrive with no template at all

0x80094801 says the request contains no certificate template information. That is normal for a request generated outside Windows – an appliance, an OpenSSL command line, a load balancer – which has no idea that templates exist. The supported route is to submit it against a named template with certreq -submit -attrib "CertificateTemplate:<name>", rather than to make the CA guess.

Key length refusals

0x80094811 is a different refusal that often follows a template change: the public key in the request does not meet the minimum size the template requires. Devices that generate keys in hardware are the usual source, because their key size is fixed by the firmware. Raise the request’s key size if you can, and if you cannot, the decision is whether that device belongs in your PKI at all rather than whether to lower the template’s floor.

When a licence is the actual fix

Publishing a template, fixing an ACL and correcting a compatibility level are all free, and they close most of these cases. There is one that they do not. If the template needs a certification authority version newer than the one you are running – and the giveaway is that the template never appears in the list of templates you can add – then the CA itself is the limit, and a template’s compatibility level cannot be lowered without giving up the features that required it. Where the CA is running on a Windows Server build that is out of support, that is the moment to move it rather than work around it, and Arco supplies Windows Server 2025 Standard with the client access licences that go with it. Check first: if the template simply is not published, publish it and spend nothing.

Every code this article covers

Code What it points at Source
0x80094800 CERTSRV_E_UNSUPPORTED_CERT_TYPE: the requested certificate template is not supported by this CA Microsoft Learn
0x80094813 CERTSRV_E_UNKNOWN_CERT_TYPE: one or more certificate templates to be enabled on this certification authority could not be found Microsoft Learn
0x80094801 CERTSRV_E_NO_CERT_TYPE: the request contains no certificate template information Microsoft Learn
0x80094811 CERTSRV_E_KEY_LENGTH: the public key does not meet the minimum size required by the specified certificate template Microsoft Learn

Confirm the fix worked

  1. certutil -CATemplates on the CA lists the template by its internal name.
  2. A test request against that template issues rather than being denied.
  3. No new Event ID 53 for that template in the CA’s log.
  4. No Event ID 77 at Certificate Services start-up naming the template.
  5. In a multi-CA environment, the template is published on every CA clients can reach.

Questions people ask about this

I published the template and it still fails.

Check whether Authenticated Users is still on the template’s ACL. If it has been removed, the CA cannot read the template regardless of publishing, and the published fix is to give every CA computer account Read.

Why does the template not appear in the list I can add?

Because its compatibility settings name a certification authority version newer than the CA you are running. That is a capability limit, not a permission.

What name does certutil -SetCATemplates want?

The template’s internal name, not its display name. They are often different, and a wrong name publishes nothing without complaining.

An appliance’s request is rejected with 0x80094801. Is that the same problem?

No. That code means the request carries no template information at all, which is normal for a request generated outside Windows. Submit it against a named template with certreq instead.

Do I need a newer Windows Server to fix this?

Only in the version case, where the template requires a CA newer than yours. Publishing and ACL problems cost nothing to fix.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

License Error LDAP 8 strong auth required: signing and channel binding enforced on DCs Free Fix Errors 8456 and 8457: inbound or outbound replication switched off on a DC Free Fix Error 0x8009480F: the request lacks the DNS name the template demands License Error NTLM authentication blocked by policy: reading the NTLM operational log
โ† Back to Knowledge Base