首先查询下面的文章:

How to automatically enroll user and computer certificate in AD

为了避免访问出现什么问题,可以直接查看附件中的xps 文件内容

同时通过下面的文章已经提到关于根证书的部署:

Distribution of root certificate with Windows AD Certificate Services

When you install an enterprise root CA, it uses Group Policy to propagate its certificate to the Trusted Root Certification Authorities certificate store for all users and computers in the domain.

也就是说更证书 如果是部署的是 Enterprise的CA的话 根证书会自动通过组策略下发出去,下发到“Trusted Root Certification Authorities” 中