This document provides step-by-step instructions for setting up basic and advanced Active Directory Certificate Services (AD CS) lab environments. The basic lab uses two servers - one as the domain controller and one to host an enterprise root CA. The root CA issues certificates to the Online Responder service and a client computer. The advanced lab adds a subordinate CA, network device enrollment, and additional configuration steps. Both labs configure certificate templates, the Online Responder, and revocation checking to test AD CS functionality.