Setup cannot give the Certificate Enrollment Policy Web Service account List permission on the "Deleted Objects" container. ...

Setup cannot give the Certificate Enrollment Policy Web Service account List permission on the "Deleted Objects" container. The web service will not be able to detect deletion of Active Directory objects such as certificate templates. To complete Setup, a member of the Domain Admins group must manually give the Certificate Enrollment Policy Web Service account List permission on the "Deleted Objects" container in Active Directory Domain Services (AD DS).