Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Free Fix 0x8009480F

Error 0x8009480F: the request lacks the DNS name the template demands

9 min read Updated October 4, 2026 Windows Server: AD, DNS & Group Policy

Fix it now

0x8009480F is CERTSRV_E_SUBJECT_DNS_REQUIRED: the DNS name is unavailable and cannot be added to the subject alternative name. The template was told to build the name from Active Directory, the attribute it needs is empty, and the CA will not invent a name it was not given.

Run these from a machine with the Active Directory module, in an elevated PowerShell session

Get-ADComputer app01 -Properties dNSHostName | Format-List Name,dNSHostName
Get-ADUser jbloggs -Properties mail,UserPrincipalName | Format-List Name,mail,UserPrincipalName
certutil -template
  1. Establish which directory object is enrolling. A computer certificate is requested by the computer account, and the DNS name comes from that object’s dNSHostName attribute.
  2. Read the template’s Subject Name tab and note exactly which fields it builds from the directory – DNS name, email, user principal name – because the codes for the three are different and the fix is the same shape.
  3. If a domain-joined Windows machine has no dNSHostName, check its full computer name and primary DNS suffix in System Properties, then reboot so it re-registers the attribute.
  4. For a host that cannot populate the attribute itself – an appliance, a workgroup machine – either set the attribute on the directory object deliberately, or use a template that takes the subject from the request instead.

If the template is already set to supply the subject in the request, the failure is the opposite one: the request itself is missing the extension, and it is the request that has to be rebuilt.

If the certificate issues once the attribute is populated, you are done. The next section separates the two shapes of this failure, because they look identical and their fixes are opposites.

Why it happens

A certificate template chooses one of two ways to name the subject. It can build the name from Active Directory, reading attributes off the enrolling object, or it can accept whatever the requester supplies in the request. Three of the four codes in this family come from the first mode: the template asked the directory for a value, the attribute was empty, and the CA refuses to guess.

The published texts are precise about which value is missing. 0x8009480F says the DNS name is unavailable and cannot be added to the subject alternative name. 0x80094812 says the same about the email name, for the subject or the alternative name. 0x8009480D says the same about the user principal name. In every case, the object is the place to look, not the request.

0x80094803 sits with them and behaves differently. CERTSRV_E_SUBJECT_ALT_NAME_REQUIRED says the request is missing a required subject alternative name extension – it is about what arrived, not about what the directory holds. That is the code you get when the template requires a subject alternative name and the requester built a request without one, which is common with certificates generated outside Windows.

The computer object has no dNSHostName

You have this one if 0x8009480F on a machine certificate, and Get-ADComputer <name> -Properties dNSHostName returns nothing for that attribute.

  1. Check the machine’s full computer name and primary DNS suffix in System Properties. A machine with no primary DNS suffix does not populate the attribute.
  2. Correct the suffix and reboot so the machine writes the attribute back to its own object.
  3. Re-run the query and confirm the attribute now has a value, then retry enrolment.

Machines write this attribute themselves. If you set it by hand on a domain-joined machine, expect the machine to overwrite it at the next opportunity – fix the suffix rather than the attribute.

The user object has no mail or UPN value

You have this one if 0x80094812 or 0x8009480D, and the account is missing the corresponding attribute.

  1. Populate the mail attribute or the user principal name on the account, whichever the template asks for.
  2. Check whether the account is one of a class – service accounts and shared mailboxes frequently have no mail value – and fix the class rather than the individual.
  3. Retry enrolment; nothing needs restarting.

The template builds from the directory when it should not

You have this one if The enrolling object legitimately has no such attribute: an appliance, a workgroup machine, a device enrolling through an agent.

  1. Duplicate the template and set the copy to supply the subject in the request.
  2. Publish the copy and point that class of requester at it, leaving the directory-built template for domain-joined machines.
  3. Remember that a supplied-subject template puts the responsibility for correct naming on the requester, so restrict who can enrol for it.

The request itself is missing the extension

You have this one if 0x80094803, with a request generated outside Windows or by a script.

  1. Rebuild the request with a subject alternative name extension containing the names the certificate must cover.
  2. Submit it against the intended template explicitly: certreq -submit -attrib "CertificateTemplate:<name>" request.req.
  3. Check the template’s Subject Name tab to see exactly which alternative name types it requires before rebuilding.

Full reference

The four codes and what each one is asking for

Code Constant Published meaning
0x8009480F CERTSRV_E_SUBJECT_DNS_REQUIRED The DNS name is unavailable and cannot be added to the subject alternative name
0x80094812 CERTSRV_E_SUBJECT_EMAIL_REQUIRED The email name is unavailable and cannot be added to the subject or subject alternative name
0x8009480D CERTSRV_E_SUBJECT_UPN_REQUIRED The UPN is unavailable and cannot be added to the subject alternative name
0x80094803 CERTSRV_E_SUBJECT_ALT_NAME_REQUIRED The request is missing a required subject alternative name extension

The first three are about the directory object. The fourth is about the request. If you spend an afternoon populating attributes for a 0x80094803, nothing will change.

Which attribute feeds which name

Template setting Attribute read Typical failure
DNS name dNSHostName on the computer object Machine with no primary DNS suffix, or an object created by hand
User principal name userPrincipalName on the user object Service accounts created without a UPN
Email name mail on the user object Accounts that have never had a mailbox
Directory GUID objectGUID Rare; present on every object
Common name cn Rare; present on every object

Finding every object that will fail before it does

A template change that adds a required name breaks enrolment for every object missing that attribute, all at once, at the next autoenrolment cycle. Before making the change, run the query across the population: computers with no dNSHostName, or users with no mail value. Fixing forty objects on a Tuesday afternoon is straightforward; discovering them one help-desk ticket at a time is not.

Supplied subject, and why it is not the easy way out

  • A supplied-subject template trusts the requester to name itself. Whoever can enrol can ask for any name.
  • Restrict enrolment on such templates to a small group, and prefer a manual approval step where the certificates are used for authentication.
  • Keep the two kinds of template separate. A template that sometimes builds from the directory and sometimes does not is a template nobody can reason about.
  • For appliances that enrol repeatedly, consider a dedicated template with a shorter validity so that a mis-issued name has a shorter life.

Reading the template rather than guessing at it

certutil -template lists the enrolment policy templates the client can see and their settings, which is quicker than opening the console when you are on a server that has no management tools. It also confirms whether the client can see the template at all – a client that cannot see it produces a different failure entirely, and is a permissions or publishing question rather than a naming one.

Every code this article covers

Code What it points at Source
0x8009480F CERTSRV_E_SUBJECT_DNS_REQUIRED: the DNS name is unavailable and cannot be added to the subject alternative name Microsoft Learn
0x80094812 CERTSRV_E_SUBJECT_EMAIL_REQUIRED: the email name is unavailable and cannot be added to the subject or subject alternative name Microsoft Learn
0x8009480D CERTSRV_E_SUBJECT_UPN_REQUIRED: the UPN is unavailable and cannot be added to the subject alternative name Microsoft Learn
0x80094803 CERTSRV_E_SUBJECT_ALT_NAME_REQUIRED: the request is missing a required subject alternative name extension. This one is about the request, not the directory Microsoft Learn

Confirm the fix worked

  1. The attribute the template needs has a value on the enrolling object.
  2. A test enrolment issues a certificate, and its subject alternative name contains the expected value.
  3. For a supplied-subject template, the issued certificate carries the names the request asked for and no others.
  4. No further denials for that template in the CA’s log.
  5. A sweep of the object population finds no remaining objects missing the attribute.

Questions people ask about this

Can I set dNSHostName by hand?

You can, but a domain-joined machine maintains it itself and will overwrite what you set. Correct the machine’s primary DNS suffix instead, and reboot.

Why does the CA not just use the computer’s name?

Because the template told it to use a specific attribute. The CA refuses to substitute a value it was not asked for, which is the behaviour you want from something that issues identities.

What is different about 0x80094803?

It is about the request rather than the directory: the request is missing a required subject alternative name extension. Rebuild the request with the extension.

Our appliance cannot enrol at all. What should it use?

A template that supplies the subject in the request, with enrolment restricted to a small group, rather than a directory-built template it can never satisfy.

Does any of this need a purchase?

No. These are directory attributes and template settings.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix Event ID 1056: DHCP has no credentials for dynamic DNS registration on a DC Free Fix Error 8453 replication access denied: repairing AD replication permissions License Error LDAP 8 strong auth required: signing and channel binding enforced on DCs License Error Event ID 2095 USN rollback: a domain controller restored from a snapshot
โ† Back to Knowledge Base