You need to ensure that when users attempt to execute App1, the certificate for App1 is verified against a certificate revocation list (CRL)
You need to ensure that when new client computers join the domain, their computer accounts are created in OU1 by default