Hi @TonyJK ,
Typically, the root certificate for your internal PKI is distributed via GPO to all clients. This allows domain CA to issue certificate automatically .
If you install the root CA's certificate, all subordinate certificates are trusted - including certificates issued directly by your root CA, as well as any issued by any subordinate CAs. (If you have a really big PKI environment, that becomes important.)
If your root CA is a domain-joined server, the root CA certificate is automatically published to DCs and clients. The client sends a renewal request to the CA, so you automatically get a new CA certificate.
If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the email notification for this thread.
Best regards,
Yurong Dai