In Firefox, there's a configuration setting (from about:config) in Windows (not sure about other OSes) that can be used to tell Firefox to use the system certificate store for root CAs. There are also deployment mechanisms where this can be pushed as one of the default policies. [1]
The Firefox Enterprise mailing list is the place to go to for deeper level help on these things. [2]
[1]: https://wiki.mozilla.org/CA:AddRootToFirefox
[2]: https://mail.mozilla.org/listinfo/enterprise