Using Certificates with Azure AD without On-Prem CA

Hello,
So I'm trying to use certificates from Government issued common access cards to encrypt and sign emails. My goal was to use a CA on an on-prem AD and add them into there. However we do not have an on-prem, we only have an azure ad.
I've tried looking for a way to add the certificates into azure for each user but I cant find any way.
What would be the best way to resolve this.
And if its per individual computer, how do I go about that? I've tried that before and outlook trust center does not see the certs on the common access card.
Any help would be greatly appreciated, thanks!