Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Stefani,
Sure it will work, you can even use a centralized CA architecture, just make sure you can distribute these certificates to the endpoints...
Another option is to check if the AD User account is restricted (disabled, locked out, expired, passw...