When deploying a Configuration Profile to request an Active Directory device Certificate from our Microsoft 2008 Certificate Authority, the profile installs successfully and the certificate appears in Keychain Access.
When deploying a Configuration Profile to request an Active Directory device Certificate from our Microsoft 2012 Certificate Authority, the profile installs successfully but the certificate fails to appear in Keychain Access.
We migrated all of the existing certificates, configurations, templates and settings from our Microsoft 2008 Certificate Authority to a separate Microsoft 2012 Certificate Authority, so I'm assured nothing has changed there.
The only lead I have managed to locate may possibly be related to the enhanced security being enabled by default on Microsoft Server 2012 (http://technet.microsoft.com/en-us/library/hh831373.aspx#BKMK_Security).
Has anyone else experienced this issue with Microsoft Server 2012 and ultimately what was the solution? We could disable the enhanced security on the Certificate Authority, but don't really want to unless it's absolutely necessary.