Note: If you want to federate your ArcGIS Server site with a portal and want to use Active Directory and PKI with the server, you'll need to disable PKI-based client certificate authentication on your ArcGIS Server site and enable anonymous access before federating it with the portal. Although it may sound counterintuitive, this is necessary so that your site is free to federate with the active directory - How to configure AD server for client For client authentication I have done the below procedure in AD server. Start ->Administrative tool -> Internet Information Services (IIS) Manager ->Connections->authentication -> Active Directory client certificate - authentication -> Enabled. Then also am able to connect to the server without uploading the certificate. WLC and Client Certificate Authentication - Cisco Client sends its credentials to the server (username/password with PEAPv0, certificate with EAP-TLS); 3a. In case of EAP-TLS the certificate will be validated and read by the server. Usually the CN or SAN attribute found in the certificate will be used for the Active Directory lookup; 4. SharePoint claims authentication using client certificates

Client VPN Active Directory authentication doesn't need a Domain Admin account All, After some testing on an MX84, even though the Client VPN page indicates that a Domain ADMIN account is needed for authentication, I've tested with a standard Domain USER account and client authentication still works.

Configure Certificate or Smartcard Based authentication Mar 04, 2020 Guidelines for enabling smart card logon with third-party Apr 16, 2018

Azure Active Directory maps the RFC822 value to the Proxy Address attribute in the directory. Your client device must have access to at least one certificate authority that issues client certificates. A client certificate for client authentication must have been issued to your client.

