Specifies the root certificate to which DirectAccess and VPN clients should chain. This parameter is used 1. to change the ...

Specifies the root certificate to which DirectAccess and VPN clients should chain. This parameter is used 
1. to change the IPsec root certificate or 
2. to enable PKI if there is no IPsec root certificate already configured
IPsec root certificate is a global configuration, i.e. the same certificate is found on all nodes in the DirectAccess deployment. Hence, configuring the root certificate updates it on all DirectAccess servers. If the specified certificate is not found on one or more servers then the IPsec root certificate is not updated on any of the servers and the cmdlet errors out. In a load balancing scenario if one or more nodes is down when the cmdlet is run then the certificate is only updated on the nodes that are running. But the DirectAccess server Group Policy object is updated to ensure that when these computers come up load balancing is in stopped state on them due to a certificate mismatch. For the certificate change to take effect, the admin needs to install a similar certificate on them and re-run this cmdlet