I have never user Trusted People at any of the deployments I have worked on.
I base all trust decisions on Root CAs, rather than on individuals (safer,
more standards based).
Also, individuals typically have more than one certificate, rendering
Trusted Person as not that useful
Trusted Person is intended for people outside of your organization, hence
they would not have a cert in your directory.
If the cert is in your directory, it was issued by your PKI, and your root
CA is a trusted root, so no need to designate a trusted person