Hi tmorgan_mcs,
Thank you for posting in the Microsoft Community Forum.
Typically, in a Windows domain environment, a dedicated client access license is not required to issue an auto-enrollment certificate for clients in a domain. Enterprise intermediate certificate authorities (CAs) are typically responsible for issuing certificates, and in a Windows domain, domain administrators have sufficient privileges to manage and configure certificate services.
Hello, here is the relevant documentation about CAL:License your RDS deployment with client access licenses (CALs) | Microsoft Learn
Best regards
Neuvi Jiang