Edge typically shows this warning as “Your connection isn’t private”. It means Edge rejected the site’s TLS certificate before allowing a normal HTTPS connection. First check your Windows clock, then determine whether the problem affects one site, several sites, or every HTTPS site; avoid entering sensitive information until the warning is resolved.
If only one site fails, its certificate or server configuration may be at fault. If several sites fail, investigate Windows, the network, a proxy or VPN, security software, or a network device before assuming Edge itself is the cause.
Check the error code before changing anything
On the Edge warning page, select Advanced and note the error code. Common codes point to different causes:
| Error code | What it usually indicates |
|---|---|
| NET::ERR_CERT_DATE_INVALID | The certificate is expired or not yet valid, or Windows’ date, time, or time zone is wrong. |
| NET::ERR_CERT_AUTHORITY_INVALID | Edge does not trust the certificate issuer. A proxy, antivirus product, VPN, or incorrectly installed root certificate may be involved. |
| NET::ERR_CERT_COMMON_NAME_INVALID | The certificate identity does not match the hostname in the address bar. |
| NET::ERR_CERT_INVALID | Edge found a general certificate validation failure. |
Do not enter passwords, payment details, or other sensitive information while the warning is present. It is a security decision, not merely a display problem.
#1 Best Overall
1. Check Windows date, time, and time zone
A certificate is valid only within a specific date and time range. An incorrect Windows clock or time zone can make a valid certificate appear expired or not yet valid.
- Open Settings with Win+I.
- Select Time & language > Date & time.
- Turn on Set time automatically and Set time zone automatically, where available.
- Select Sync now under additional date and time settings, if available.
- Close and reopen Edge, then test the site again.
If the clock repeatedly becomes incorrect, investigate Windows Time, firmware time, or the device’s network connection rather than bypassing the warning.
2. Test the site on another network
A captive Wi-Fi portal can redirect an HTTPS request to a sign-in page. Edge may then receive a certificate or hostname that does not belong to the requested site.
- Use the network’s documented sign-in process, or open a plain HTTP page such as http://example.com to trigger the portal.
- Complete the Wi-Fi, hotel, or airport portal login.
- Reconnect and test the original HTTPS site.
- If possible, test the site using a phone hotspot.
If the site works on a hotspot but not on your normal Wi-Fi, investigate the router, DNS filtering, proxy, monitoring equipment, or captive portal. A router-attached monitoring device can also interfere with connections.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors3. Decide whether the website or your PC is at fault
| Test result | Likely fault domain |
|---|---|
| One site fails, while unrelated HTTPS sites work | The site’s certificate, hostname, server configuration, or certificate chain. |
| Several unrelated sites fail in Edge and other browsers | Windows time or certificate validation, security software, proxy or VPN, DNS filtering, or the network. |
| Several sites fail on one network but work on a hotspot | Router, captive portal, proxy, DNS filter, or network inspection device. |
| Sites fail in Edge but work in another browser | Edge profile data, extensions, browser policy, or an Edge-specific configuration. |
For a single site, select Advanced and inspect the certificate details if Edge provides them. Check that the certificate hostname matches the address bar and that its validity dates have not passed. A certificate issued for a CDN or different host does not by itself show that Edge is malfunctioning.
4. Check proxy and VPN settings
An unwanted manual proxy or incorrectly configured VPN can replace or intercept a website’s certificate, causing authority, hostname, or date errors.
Rank #2
- Open Settings > Network & internet > Proxy.
- Review Manual proxy setup. Turn off a manual proxy you do not recognize or need.
- Disconnect the VPN temporarily, then test the same site.
- If the VPN is required for work, check its web filtering and traffic-inspection options with your administrator.
Do not remove an organization-managed proxy without consulting your administrator. Corporate proxies may inspect HTTPS traffic and install a company root certificate intentionally.
5. Temporarily test antivirus HTTPS scanning
Some antivirus, endpoint-security, parental-control, and DNS-filtering products inspect encrypted traffic. If their certificate configuration is misconfigured, outdated, or partially removed, Edge may reject the certificate.
- Open the security product’s settings.
- Look for HTTPS scanning, encrypted connection scanning, SSL inspection, or web protection.
- If the product allows it safely, disable the feature only long enough to test.
- Test several unrelated HTTPS sites.
- Re-enable the feature after testing. If it caused the problem, update or repair the product or contact its vendor.
Do not permanently leave antivirus protection off. Correct the product’s installation or certificate configuration instead.
6. Test Edge without extensions
Extensions are less likely than a clock, certificate, or network interceptor to cause this warning, but disabling them can rule out browser-level interference.
- Select … (Settings and more) > Extensions > Manage extensions.
- Turn off all extensions.
- Close and reopen the tab, then test the site.
- If the warning disappears, turn extensions back on one at a time.
You can also test in an InPrivate window. If the same certificate error appears in InPrivate and other browsers, an extension or ordinary Edge cache is less likely to be the cause.
7. Clear Edge browsing data
Clearing cookies and cached files can remove stale browser data or a broken site session. It cannot repair an expired, revoked, mismatched, or untrusted website certificate, or fix certificate interception by a proxy or antivirus product.
Free tools Windows power users keep installed
One-click scans. No signup required.
- In Edge, select … > Settings.
- Open Privacy, search, and services.
- Under Clear browsing data, select Choose what to clear.
- Choose a time range.
- Select Cookies and other site data and Cached images and files.
- Select Clear now, then restart Edge.
Open this Edge settings area directly by entering edge://settings/privacy in the address bar.
8. Clear Windows SSL state
Clearing cached SSL session state is reasonable if a site certificate has recently changed. It does not make an expired, revoked, mismatched, or untrusted certificate valid.
- Press Win+R.
- Enter inetcpl.cpl and press Enter.
- Open the Content tab.
- Select Clear SSL state.
- Restart Edge and test again.
9. Inspect trusted certificates carefully
To inspect certificates for the current Windows user:
- Press Win+R.
- Enter certmgr.msc and press Enter.
- Open Trusted Root Certification Authorities > Certificates.
- Look for a certificate you can positively identify as incorrectly installed or left behind by removed software.
Do not delete a certificate merely because its name is unfamiliar. Enterprise management, antivirus, VPN, filtering, and inspection products may deliberately install trusted roots. Remove only a certificate you can positively identify as incorrect, following the issuing product’s or organization’s instructions. Never install an arbitrary certificate downloaded from the Internet.
10. Reset Edge settings
If the problem is limited to Edge and persists after extension testing, restore Edge’s browser settings:
- Select … > Settings.
- Select Reset settings.
- Select Restore settings to their default values.
- Select Reset.
This resets browser settings; it does not replace Windows trusted-root certificates or correct a server-side certificate.
Rank #4
11. Repair Windows system files
Use these commands if multiple browsers have certificate or networking problems and Windows files may be damaged. Open Command Prompt as administrator and run each command separately:
- Run sfc /scannow.
- Run DISM /Online /Cleanup-Image /RestoreHealth.
Restart Windows after the scans complete, then test again. These commands repair Windows component and system files; they do not directly repair a website’s TLS certificate.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →12. Reset networking only after safer tests
If multiple sites are affected and the TCP/IP or Winsock configuration may be damaged, open Command Prompt as administrator and run these commands separately:
- Run netsh winsock reset.
- Run netsh int ip reset.
- Run ipconfig /release.
- Run ipconfig /renew.
- Run ipconfig /flushdns.
Restart the PC after Winsock or IP reset operations. You may need to reconnect to Wi-Fi or reconfigure networking.
netsh advfirewall reset resets Windows Defender Firewall policy to defaults and can remove custom firewall rules. It is not a harmless first step; use it only when you understand the impact or are following a documented IT procedure.
What not to use as a fix
- Do not use “proceed anyway” for a site handling passwords or payments. Edge has not verified the connection identity.
- Do not type “thisisunsafe” as a routine solution. It is an undocumented emergency bypass, not a certificate repair, and may not work with HSTS or organizational policies.
- Do not launch Edge with “–ignore-certificate-errors”. This disables certificate validation and exposes browsing sessions to man-in-the-middle attacks.
- Do not turn off Edge security settings as a general remedy. Enhanced Security Mode does not make an invalid certificate valid.
- Do not reinstall Edge expecting it to repair Windows trust. Reinstallation usually leaves the trust store, proxy, VPN, antivirus, router, and network path unchanged.
When HSTS prevents a bypass
If the warning mentions HSTS, Edge intentionally will not offer the ordinary bypass. HSTS requires the site to use HTTPS and tells the browser not to accept an insecure fallback. Fix the clock, network, certificate, proxy, or server instead of weakening Edge’s security controls.
Best Value
When to contact the website or administrator
Contact the site owner when only that site fails and the certificate shows an expired date, hostname mismatch, invalid chain, or another server-side problem. Include the exact hostname and error code, such as NET::ERR_CERT_COMMON_NAME_INVALID; do not send passwords or private certificate-store data.
Contact your organization’s IT team when the PC uses a managed proxy, VPN, endpoint inspection, or enterprise certificate. Contact the network owner when the warning appears only on one Wi-Fi network, especially if a captive portal or monitoring device is involved.
FAQ
Why does Edge say “Your connection isn’t private” on every website?
Likely causes include an incorrect Windows clock, Windows certificate validation, HTTPS inspection by antivirus or a proxy, a VPN, DNS filtering, or a network device. Compare Edge with another browser and test using a phone hotspot to narrow down the cause.
Can clearing the Edge cache fix the certificate warning?
It can remove stale cookies or cached files, but it cannot repair an expired, revoked, mismatched, or untrusted certificate. It also cannot fix a wrong system clock or certificate replacement by antivirus, a proxy, or a VPN.
Recommended Free Tools
What does NET::ERR_CERT_COMMON_NAME_INVALID mean?
The certificate identity does not match the hostname in Edge’s address bar. The site may be incorrectly configured, or a proxy, security product, captive portal, or network device may be presenting a certificate for another host.
Why is there no option to continue to the site?
The site may use HSTS, which prevents Edge from offering an ordinary insecure bypass. Correct the certificate, clock, or network problem instead of disabling certificate validation.
Should I delete unknown certificates from Trusted Root Certification Authorities?
No. Enterprise management tools, antivirus, VPNs, and HTTPS inspection products can install trusted roots deliberately. Delete a certificate only when you can positively identify it as incorrect and understand which product or administrator installed it.
Will reinstalling Microsoft Edge fix this error?
Usually not. Reinstalling Edge does not normally change Windows’ certificate trust store, proxy settings, VPN configuration, antivirus HTTPS scanning, router behavior, or the website’s certificate.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchThe Bottom Line
First check the Windows clock, then determine whether the warning affects one site, several sites, or every HTTPS site. Test another network and review proxy, VPN, and HTTPS-scanning settings. Clear Edge data or reset Edge settings only for browser-specific problems, inspect certificates cautiously, and avoid undocumented bypasses or disabling certificate validation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

