Test environment in Hyper-V (Windows 2012 R2 Hyper-V).
DC1, DC2, some role-based servers (Exchange, SharePoint etc) - all under Windows 2012 R2
Windows 8.1 Pro (as workstation).
Domain like office1.company.local
In DC1 I added role AD Certificate Services. After that, the certificate with name office1-DC1-CA is visible in all certification stores (certmgr.msc) in all machines and under all users in domain in TRCA (Trusted Root Certification Authorities).
The question was: why? In all appled group policies I don't see nothing to this certificate. In what way this certificate shown in cert's store, in what method it be appled?