Certificate Policies are centralized rules and templates for requesting and issuing certificates. They define, for example, which Certificate Provider is used, which validity periods, key lengths, or intended uses are permitted, and which additional requirements apply to a certificate request.
This helps standardize certificate requests and consistently enforce security policies.
https://youtu.be/srk8XTCZv1E?si=3wkDhp47MGv2OJAP