Make sure you choose the copied template that you created and not the original (i.e., select Exchange User Custom, not Exchange User). Next you need to enable the Group Policy for the autoenrollment.
To do so, perform these steps: Open the GPO that applies to the container (e.g., domain or OU that will affect the users/computer requiring autoenrollment) or create a new GPO.
The Certificate Services MMC Snap-in (certsrv.msc) is your primary PKI administrative console.
You should try to spend some time with this MMC Snap-in and get familiar with the tool, since it gives you a deeper insight into the world of a Microsoft based PKI.
Don’t enable digital signature publishing in AD (this is not needed for signatures because the certificate is enabled in the payload of the message sent). Alternatively, if you have archiving enabled, you can select the "Archive subject’s encryption private key" (the option might be grayed out depending on the type of certificate you’re duplicating).