Hello Shlomit S,
Thank you for posting in Microsoft Community forum.
You can configure user certificate auto-enrollment via GPO, this can enroll user certificates for AD users.
Or you can enroll a user certificate manually, then set logon script for this user to install this certificate when he/she logs on any machine.
I hope the information above is helpful.
If you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou