Configure Windows Server CA to accept SAN Run cmd as an admin and execute: certutil -setreg policy\EditFlags +EDITF_ATTRIBUTESUBJECTALTNAME2