You need to ensure that a user named User1 can decrypt private keys archived in the Active Directory Certificate Services (AD CS) database