In the certificate template (assuming v2 since you are talking about autoenrollment), ensure that the Request Handling tab is configured to Delete revoked or expired certificates (do not archive). This is the switch that is used by autoenrollment (and normal enrollment) to determine whether to remove the certificate from the store or not. It has expired. The issuing Certificate Authority (CA) did not add that certificate to the Transparency Log (TL) OR; The website owner requested the issuing CA not to add the certificate to the Transparency Log (TL), perhaps for privacy reasons, etc. Note that Certificate Transparency (CT) is a critical requirement for all Certificate Authorities.