Yes, a dedicated Root CA can be established as part of MTG Corporate PKI. The Root Certification Authority forms the highest trust authority within a PKI and is configured accordingly during deployment.
Its role is to use its private key to sign one or more subordinate Certification Authorities (Sub CAs). This establishes trust in the issuing CAs and ensures that certificates within the PKI are based on a reliable chain of trust.
Because a Root CA contains particularly sensitive cryptographic key material, protecting this material is essential. For this reason, the key material should be strongly secured and protected in Hardware Security Modules (HSMs).