Step 1 - Create a security group
To create a security group on Active Directory
On DC1, click Start > Administrative Tools, and then click Server Manager.
In the navigation pane, expand Roles, expand Active Directory Domain Services, expand Active Directory Users and Computers, expand contoso.com, right-click Users, click New, and then click Group.
In the New Object - Group dialog box, in the Group name text box, type a name for the group. Example: AutoEnrollGroup.
Click OK. Leave Server Manager running with the Computers container shown in the results pane.
Step 2 - Create a certificate template to enroll
To create a certificate template
Open the Certificate Templates Console
From the Start menu, click Run.
Type certtmpl.msc in the text box and click OK. Certificate Templates Console window appears on the page.
Under General tab,
Type a Template display name. For example, User Auto Enroll.
(Optional) Modify the default Validity Period and Renewal Period as per your requirements.
Select Publish certificate in Active Directory check box.
reference:https://docs.druva.com/Knowledge_Base/inSync/How_To/How_to_set_up_automatic_certificate_enrollment_in_Active_Directory