You need to minimize the amount of time it takes for client computers to download a certificate revocation list (CRL)
You need to deploy the new security settings only on the IIS servers that are members of the Web organizational unit
You need to configure your partner company’s domain to use the approved set of administrative templates