TABLE 1: User PKI Trust Management Mechanisms
MechanismScopeManaged ByManagement Interface or Mechanism
Machine certificate storeMachineLocal AdministratorMMC Certificates snap-in
User certificate storeUserUserMMC Certificates snap-in, IE certificates viewer
Enterprise Trust (CTLs)Depends on the AD object that the GPO is linked toGPO AdministratorGPO Editor
Trusted root CAsDepends on the AD object that the GPO is linked toGPO AdministratorGPO Editor, certutil.exe -dspublish RootCA command
NTAuth storeForestForest or Domain AdministratorCertutil.exe -dspublish NTAuth command
Windows UpdateAll machines with the Root Certificate Update Service enabledForest or Domain Administrator, MicrosoftMicrosoft Root Certificate Program