Hi,
Based on my understanding , you have an CA act as an Enterprise and root CA, right?
If i misunderstand you ,please feel free to let me know.
In the PKI environment , it is not supported to renew the root ca certificates automatically.
You don' t need to do anything.
https://social.technet.microsoft.com/Forums/lync/en-US/196a6229-c118-49e7-b073-df79e71ce5b1/auto-renew-an-enterprise-ca-root-certificate?forum=winserversecurity
If you mean the certificates issued by CA for the clients and users , yes ,it can be set not to renew automatically.
The certificates by the ca issued will not auto-enroll by default if the requirements didn't been meet:
auto-enroll group policy
auto-enroll permission for the templates
https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-autoenrollment
Best Regards,