Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Edge can manage certificates from its own settings, but the right installation method depends on what the certificate is for. Use Edge’s certificate manager for a user CA or client certificate. Use the Windows certificate store for an IE-mode add-on publisher certificate, and place an internal CA root in the trusted-root store rather than in Trusted Publishers.

These instructions apply to Edge on Windows and macOS. The current Edge certificate-management experience is available from Edge 136; the related management policy is supported on Windows and macOS from Edge 133. Android and iOS do not support this certificate-management interface.

Add a certificate through Edge settings

  1. Open Microsoft Edge.
  2. Select Settings and more (…) in the upper-right corner, then select Settings.
  3. Open Privacy, search, and services.
  4. Scroll to Security.
  5. Select Manage certificates.
  6. In the certificate-management page, select Import.
  7. Choose the certificate file and complete the import wizard. You may need to enter the certificate password if the file is protected.

The certificate file normally has a .cer, .crt, .pem, .p12, or .pfx extension. A .pfx or .p12 file commonly contains a private key and will usually require a password. Do not import a private-key certificate into a shared or unmanaged computer unless you know who can access the key.

Open Edge’s certificate manager directly

If Security or Manage certificates is not displayed, enter this internal address in Edge’s address bar:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Symantec VIP Hardware Authenticator - K10S - Two Factor Authentication Security Key - Fits USB-A - FIDO U2F Certified
  • Standard OATH compliant HOTP (event-based). The HOTP function is to be used with Symantec VIP Access.
  • Generates a 6-digit HOTP code with one tap of the touch button
  • FIDO U2F support with Symantec VIP attestation certificate
  • Zero footprint: no need for the end user to install any software
  • Micro-sized, secure, sturdy, and long-life hardware design
edge://settings/privacy/manageCertificates

Press Enter, then select Import. This direct route was particularly useful when a rendering problem in Edge 131 on Ubuntu hid the certificate-management controls.

Choose the correct certificate type

What you are installing Where to install it Purpose
Internal CA or self-signed CA Edge certificate manager, or the platform trust store where appropriate Allows sites signed by that CA to be trusted
Client certificate Edge certificate manager Identifies you or your device to a website that requests client-certificate authentication
IE-mode ActiveX/add-on publisher certificate Windows Trusted Publishers store Allows Windows to verify the publisher of the add-on
Root CA for an IE-mode add-on publisher Windows Trusted Root Certification Authorities store Trusts the internal CA that issued the publisher certificate

Installing a certificate does not make every website trust it. The certificate must be issued for the intended purpose, and the browser or operating system must use the store where it was installed.

Install a Windows certificate for IE mode

For a publisher certificate used by an IE-mode ActiveX control or add-on, use the Windows certificate manager rather than Edge’s import page:

  1. Press Windows key + R, type certmgr.msc, and press Enter.
  2. Expand Trusted Publishers, then select Certificates.
  3. Right-click Certificates and select All Tasks > Import….
  4. Complete the certificate-import wizard.

If the publisher certificate was issued by an internal CA, import the CA’s root certificate separately:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. In certmgr.msc, expand Trusted Root Certification Authorities.
  2. Select Certificates.
  3. Right-click Certificates, select All Tasks > Import…, and complete the wizard.

These stores have different jobs. The publisher’s signing certificate belongs in Trusted Publishers; its issuing root CA belongs in Trusted Root Certification Authorities. Importing only one may still leave an IE-mode add-on blocked.

Rank #2
Thales - SafeNet eToken Fusion - Phishing-Resistant FIDO2 Certified Security Key for Digital Certificates or Web Apps & Desktop Authentication - USB-A - Pack of 1
  • PKI FIDO2 SECURITY KEY: This USB-A security key combines X509 digital certificates (PKI) and FIDO for maximum protection. Supports digital signatures, file encryption, and phishing-resistant authentication based on FIDO or PKI. FIDO 2.0 level 1 and U2F certified
  • PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
  • BROAD COMPATIBILITY: Works with Windows, Linux and USB-A devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, ensuring secure use across various platforms, including Thales, Microsoft, AWS, and Google
  • ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
  • THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts

Deploy a certificate with Windows Group Policy

On a managed Windows computer, an administrator can deploy an IE-mode publisher certificate through Group Policy:

  1. Run gpedit.msc.
  2. Go to Computer Configuration > Windows Settings > Security Settings > Public Key Policies > Trusted Publishers.
  3. Import the publisher certificate into that policy store.

After changing relevant policies, run:

gpupdate /force

Then restart Edge. IE mode also uses Internet Explorer security-zone settings. To inspect those settings, run inetcpl.cpl, select the applicable zone on the Security tab, and review its configuration.

Why Edge still does not select a client certificate

A client certificate is not automatically used simply because it was imported. The website must request a client certificate during TLS authentication, and the certificate must meet that request. Edge may omit an installed certificate when its issuer, subject, key usage, or other properties do not match what the server accepts.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

By default, Edge does not automatically select a client certificate for any site. Administrators can configure automatic selection with the Automatically select client certificates for these sites policy, whose identifier is AutoSelectCertificateForUrls.

For example, a policy entry with an empty filter permits any eligible client certificate that satisfies the server’s request:

Rank #3
Thetis PRO-A for Business - USB A FIDO2 Security Key L1 MFA & Passkey Access for School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesfore - 2 Pack
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-A & NFC): The Thetis PRO-A features integrated USB Type A and NFC for a near-instant account unlock. Simply unfold the key and hold it to your smartphone’s NFC antenna to authenticate on the go.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
{"pattern":"https://www.contoso.com","filter":{}}

A more restrictive entry can filter by issuer and subject:

{"pattern":"https://www.contoso.com","filter":{"ISSUER":{"CN":"Certificate Issuer Name"},"SUBJECT":{"CN":"Certificate Subject Name"}}}

The ISSUER and SUBJECT sections can be combined, in which case both must match. Organization (O) and organizational-unit (OU) matching requires at least one matching value.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure certificate-management policy on a managed device

An organization controls whether users can change certificate settings with Allow users to manage installed CA certificates. Its policy identifier is CACertificateManagementAllowed.

Value Effect
0 — All Users can manage all certificates.
1 — UserOnly Users can manage certificates they imported, but cannot change trust settings for Edge’s built-in certificates.
2 — None Users can view certificates but cannot manage them.

In Group Policy, find it at Administrative Templates > Microsoft Edge > Certificate management settings.

On Windows, the corresponding registry setting is:

HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftEdge
Value name: CACertificateManagementAllowed
Type: REG_DWORD
Example: 0x00000001

Do not change a work or school computer’s certificate policy without the administrator’s approval. The organization may instead deploy CA certificates using policies such as CACertificates, CACertificatesWithConstraints, CADistrustedCertificates, or CAHintCertificates.

Rank #4
Thales - SafeNet eToken Fusion - Phishing-Resistant FIDO2 Certified Security Key for Digital Certificates or Web Apps & Desktop Authentication - USB-A, Pack of 10
  • PKI FIDO2 SECURITY KEY: This USB-A security key combines X509 digital certificates (PKI) and FIDO for maximum protection. Supports digital signatures, file encryption, and phishing-resistant authentication based on FIDO or PKI. FIDO 2.0 level 1 and U2F certified
  • PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
  • BROAD COMPATIBILITY: Works with Windows, Linux and USB-A devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, ensuring secure use across various platforms, including Thales, Microsoft, AWS, and Google
  • ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
  • THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Fix common certificate problems

“Manage certificates” is missing

Open edge://settings/privacy/manageCertificates directly. If the page still does not provide management controls, check the Edge version and whether the device is managed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Import button is disabled

The CACertificateManagementAllowed policy may be set to 2 (None). Open edge://policy to inspect policies applied to Edge, then contact the administrator if the setting is enforced.

A built-in certificate cannot be edited

With the UserOnly value (1), Edge permits management of user-imported certificates but does not permit changes to the trust settings of built-in certificates. This is expected behavior, not an import failure.

The site says the certificate is untrusted

Confirm that you imported the CA certificate, not only the site’s leaf certificate, and that the certificate is valid for server authentication. Check the certificate’s expiration date, subject, issuer, and trust chain. Also verify that you installed it in the profile or platform store Edge is actually using.

Edge never prompts for the client certificate

Check that the server is requesting client authentication and that the certificate contains a usable private key and matches the server’s issuer and usage requirements. If multiple certificates are eligible, an administrator can configure AutoSelectCertificateForUrls for the site. Importing a certificate alone does not force a prompt or automatic selection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Thetis Nano-A for Business - USB A FIDO2 Security Key L1 MFA & Passkey Access for School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesfore - 2 Pack
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • USB TYPE A Connectivity & DONGLE Design: Designed for PCs, Macs, laptops and Android devices that utilize a USB-A port. Plug and stay, or carry it on a keychain. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC functionality is not supported.

Windows blocks an IE-mode add-on

The message “Windows has blocked this software because it can’t verify the publisher” can indicate that the add-on is unsigned, its signing certificate is expired, or the certificate is not trusted. Import the publisher certificate into Trusted Publishers and, when applicable, import its internal CA root into Trusted Root Certification Authorities.

FAQ

Where is certificate management in Microsoft Edge?

Go to Settings and more (…) > Settings > Privacy, search, and services > Security > Manage certificates. You can also open edge://settings/privacy/manageCertificates directly.

Can I add a certificate to Edge on Android or iPhone?

The current Edge certificate-management experience is supported on Windows and macOS, not Android or iOS. Mobile certificate installation must follow the device operating system’s certificate and management procedures.

Does importing a client certificate make Edge use it automatically?

No. The website must request client-certificate authentication, and the certificate must match that request. Automatic selection requires the AutoSelectCertificateForUrls policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where should an IE-mode publisher certificate be installed?

On Windows, open certmgr.msc and import it under Trusted Publishers > Certificates. If an internal CA issued it, import that CA’s root under Trusted Root Certification Authorities.

Why can I view certificates but not import or remove them?

An administrator may have set CACertificateManagementAllowed to 2 (None), which allows viewing but blocks certificate management.

The Bottom Line

For a normal user CA or client certificate, use Settings and more > Settings > Privacy, search, and services > Security > Manage certificates, or open edge://settings/privacy/manageCertificates. For IE-mode add-ons, use Windows Trusted Publishers and install the issuing root CA separately when required. If Edge installs the certificate but does not use it, check the server’s certificate request and any organization policies before importing it again.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.