Policies in domain and GPO are ok
Templates are ok
In fact certutil -pulse is working, gpupdate /force is working
But, a computer without certificate, is not autoenroling. Neither if I delete the right certificate, immediatelly restart, then no autoenrolment again. I need to trigger manually with certutil -pulse or gpupdate.
Please help!!!