Your network contains an Active Directory domain named contoso.com.
The domain contains a server named Server1 that runs Windows Server 2012.
Server1 has the Active Directory Certificate Services server role installed and is configured as an enterprise
certification authority (CA).
You need to ensure that all of the users in the domain are issued a certificate that can be used for the following
purposes:
Email security
Client authentication
Encrypting File System (EFS)
Which two actions should you perform? (Each correctanswer presents part of the solution. Choose two.)
A.
Modify the properties of the User certificate template, and then publish the template.
B.
From a Group Policy, configure the Certificate Services Client – Certificate Enrollment Policy settings.
C.
From a Group Policy, configure the Automatic Certificate Request Settings settings.
D.
Duplicate the User certificate template, and thenpublish the template.
E.
From a Group Policy, configure the Certificate Services Client – Auto-Enrollment settings.
http://technet.microsoft.com/en-us/library/cc731242%28v=ws.10%29.aspx
http://technet.microsoft.com/en-us/library/cc770857%28v=ws.10%29.aspx
http://technet.microsoft.com/en-us/library/cc770794%28v=ws.10%29.aspx
And Something Xtra:
http://blogs.technet.com/b/mspfe/archive/2012/12/27/how-to-avoid-having-users-enroll-for-multiple-certificates.aspx