In order for Microsoft Exchange ActiveSync to authenticate a user from a certificate, it must first trust the source of the certificate.

  1. On the Certificate Authority server, select Start > Run.
  2. Type MMC in the dialog box and press Enter to launch the Microsoft Management Console (MMC).
  3. Click File > Add/Remove Snap-in… from the MMC main menu.
  4. Select Enterprise PKI from the list of Available snap-ins and then select Add.

  5. Click OK.

  6. Right-click Enterprise PKI and select Manage AD Containers.

  7. Select the NT AuthCertificates tab and verify the Certificate Authority is listed. If not, select Add to add the Certificate Authority to the group.
  8. Click OK.