There is enough detail on msdn regarding this topic. But what I wanted to make clear is what actually happens in the background.
MSDN tells you to tick the Secure by legal entity or by address book.
http://technet.microsoft.com/en-us/library/gg731852.aspx
This triggers a change in the AOT by enabling two policies.
The reason I mention this is – if you happen to do this in the usr layer. Remember to move it to a layer that will be part of the release.