Originally Posted by Microsoft
In Windows Vista and Windows 7, root certificates are automatically updated when a user visits a secure Web site (by using HTTPS), reads a secure email (S/MIME), or downloads an ActiveX control that is signed (code signing) and encounters a new root certificate. This process is seamless to the user, so no security dialog boxes or warnings are displayed.