Sure - just poor wording from me.
I guess this is reassuring:
"These are the machines that are allowed to access the certificates and private keys. A credential handle retrieved by the IdP is also needed, so a compromised VDA account in this group has limited scope to attack the system."