Hi Manish Rahul
I think the safest way to audit certificate template ACLs is to start by pulling the template’s security descriptors and reviewing which groups have Enroll and Autoenroll rights. You’ll usually find that some broad groups (like Domain Users) sneak in there unintentionally. From there, trim down access by removing auto-enrollment from groups that shouldn’t have it, but keep Read permissions intact so you don’t break existing templates. A good practice is to test changes in a lab or apply them to a pilot OU first, so you can confirm that legitimate enrollments still work. Also, document the ACL changes so you’ve got a clear record of who can enroll what it’ll save headaches later.
If this clears things up and helps you move forward, go ahead and hit “accept answer” so others know it worked for you.