Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Microsoft Edge uses certificates for two different jobs that are easy to confuse:

  • CA certificates establish whether a website’s TLS certificate can be trusted.
  • Client certificates identify the browser to a server when a site requires mutual TLS (mTLS).

Edge’s certificate-management experience for installed CA certificates is available starting with Edge 136. Administrators can control it with policy, while Windows domain administrators can continue deploying certificates through Windows Group Policy. Client-certificate selection is controlled separately.

What Edge certificates do

When you open an HTTPS site, Edge validates the server’s certificate chain. It checks the certificate’s signature, validity dates, hostname, revocation-related requirements, and whether the issuing chain leads to a trusted CA. A private key normally stays with the certificate owner and is used to prove possession when needed; it should not be exported or shared casually.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There are two important certificate categories:

Certificate type Used for Relevant Edge controls
CA or server-trust certificate Deciding whether a website’s TLS certificate is trusted CACertificateManagementAllowed, CACertificates, CACertificatesWithConstraints, CADistrustedCertificates, CAHintCertificates
Client certificate Authenticating the browser or user to a server requesting client authentication AutoSelectCertificateForUrls, PromptOnMultipleMatchingCertificates

Installing a CA certificate will not make Edge automatically choose a client certificate, and configuring automatic client-certificate selection will not make an untrusted website certificate trusted.

#1 Best Overall
Sale
Identiv SCR3310V2 USB Smart Card Reader Writer CAC/PIV
  • Fully Compliant - Complies With All Major Industry Standards, Including Iso/Iec 7816, Usb Ccid, Pc/Sc, And Microsoft Whql. As Well As, Emv 2011 Ver 4.3 Level 1 And Gsa Fips 201.
  • Seamless Integration - With Identiv-Specific Smartos You’Ll Get Easy, Complete Support Of All Major Contact Smart Card Ics And Technologies In One Simple Reader.
  • Universal Compatibility - Works With Virtually All Contact Chip Cards And Pc Operating Systems, Including Windows, Macos, Linux And Android.
  • Fast And Convenient- Shorten Your Transaction Time With A Reader That’S Optimized For Speed. It’S Ultra-Compact And Robust Design Is Streamlined For Mobile Operation, Making This Reader The Best Choice For Convenience, Security And Reliability.
  • Ergonomic and cost efficient design

Manage installed CA certificates in Edge

On Edge 136 and later, open Edge’s Settings and search for certificate or manage certificates. The certificate-management page is available through the browser’s privacy and security settings. The exact label and layout can vary by Edge release and operating system.

  1. Open Microsoft Edge.
  2. Open edge://settings.
  3. Use the Settings search box and search for certificate.
  4. Open the certificate-management option shown by your installation.
  5. Review the installed CA certificates and use the available management action, such as adding or removing a certificate, only when you understand which trust decisions it changes.

If the management controls are missing or disabled, the browser may be managed by an administrator. The policy controlling this experience is Allow users to manage installed CA certificates (CACertificateManagementAllowed).

Certificate-management policy values

Value Name Effect
0 All Users can manage all certificates.
1 UserOnly Users can manage user certificates. Trust settings for built-in certificates cannot be changed.
2 None Users cannot manage certificates, although they can view them.

This policy is per profile, but it does not apply to a profile signed in with a Microsoft account. It is supported from Edge 136.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Control certificate management with Group Policy

On Windows, install the current Microsoft Edge administrative templates, then open the Group Policy editor and go to:

Computer Configuration or User Configuration
> Policies
> Administrative Templates
> Microsoft Edge
> Certificate management settings
  1. Open Allow users to manage installed CA certificates.
  2. Select Enabled.
  3. Choose the required value: All, UserOnly, or None.
  4. Apply the policy and refresh Group Policy.
  5. Close and reopen Edge before testing the browser UI.

Force a refresh from Command Prompt or PowerShell with:

gpupdate /force

Check what Edge actually received by opening:

edge://policy

Look for CACertificateManagementAllowed and confirm that the expected value is shown. A policy can be correctly configured in Group Policy but still appear unchanged in Edge until the browser is restarted.

Set the policy through the registry

For a computer-level policy, the registry location is:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
ZOWEETEK CAC Card Reader Military, USB Smart Card Reader for Windows Mac
  • Advanced Realtek Chipset; PIV, EMS, ISO-7816 & EMV2 2000 Level 1, CE, FCC, VCCI and Microsoft WHQL certifications.
  • Supports ActivClient, AKO, OWA, DKO, JKO, NKO, BOL, GKO, Marinenet, AF Portal, Pure Edge Viewer, ApproveIt, DCO, DTS, LPS, Disa Enterprise Email and etc. CAC chip cards
  • Sleek ergonomic flat design, precise slot, convenient to horizontally plug card
  • Compatible with Windows10/11, Mac OS 10.15 or later. Driver free, plug and play.
  • New generation DOD Military CAC USB smart chip card reader, no firmware upgrade requirements
HKLMSOFTWAREPoliciesMicrosoftEdge

Create or modify this value:

Name: CACertificateManagementAllowed
Type: REG_DWORD
Example: 0x00000001

For example, this command allows users to manage user certificates only:

reg add "HKLMSOFTWAREPoliciesMicrosoftEdge" /v CACertificateManagementAllowed /t REG_DWORD /d 1 /f

After changing it, run gpupdate /force if appropriate, restart Edge, and verify the result at edge://policy. Registry policy changes should be made through your organization’s configuration process rather than manually on production machines.

Deploy certificates through Windows instead of the Edge UI

Edge’s certificate-management UI is not a replacement for enterprise certificate deployment. Windows domain administrators can deploy certificates with Group Policy from:

Computer Configuration
> Policies
> Windows Settings
> Security Settings
> Public Key Policies
  1. Open the target certificate store, such as Trusted Root Certification Authorities.
  2. Right-click the store and select Import.
  3. Choose the certificate file and complete the Certificate Import Wizard.
  4. Link the Group Policy Object to the computers or users that need the certificate.

Use a trusted root only when you intentionally want the issuing CA to trust server certificates. Adding a company inspection CA, lab CA, or self-signed root broadly can allow that CA to intercept or impersonate TLS connections.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use certificates from the operating system trust store

The policy Use user-added TLS certificates from platform trust stores for server authentication (CAPlatformIntegrationEnabled) controls whether user-added certificates from the operating system’s platform trust store participate in TLS server-certificate path building.

  • Enabled or unset: user-added platform certificates are used.
  • Disabled: they are not used.

On Windows and macOS, this policy is supported from Edge 133. Android support begins with Edge 138; iOS does not support this policy.

Its Windows Group Policy location is:

Administrative Templates
> Microsoft Edge
> Certificate management settings

The Windows registry value is:

CAPlatformIntegrationEnabled

It is a REG_DWORD; 0x00000000 disables platform integration. For example:

Rank #3
Sale
Identiv SCR3500 Smartfold Smart Card Reader
  • Compact And Lightweight Dongle Form-Factor Card Reader
  • Accepts Cards In Id1 Format (Iso8716)
  • Ccid Compliant
  • Compact and lightweight dongle form-factor card reader
  • Accepts cards in ID1 format (ISO8716)
reg add "HKLMSOFTWAREPoliciesMicrosoftEdge" /v CAPlatformIntegrationEnabled /t REG_DWORD /d 0 /f

Do not use the old MicrosoftRootStoreEnabled advice found in older troubleshooting guides. That policy was removed from current Edge: Windows and macOS in Edge 115, Linux in Edge 120, and Android in Edge 121. It no longer controls certificate verification in current Edge.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure automatic client-certificate selection

A server using mTLS sends a certificate request to Edge. The browser then needs to choose an eligible client certificate, usually one with a private key. The policy for automating that choice is AutoSelectCertificateForUrls.

The policy is a list of strings. Each string contains a stringified JSON dictionary with a URL pattern and a filter:

{
"pattern": "https://example.com",
"filter": {
"ISSUER": {
"CN": "Example Issuing CA"
}
}
}

The ISSUER.CN filter limits selection to certificates issued by a CA with that Common Name. Edge still considers the server’s certificate request: a certificate that does not match what the server requests is not eligible, even if it matches the configured filter.

If both ISSUER and SUBJECT filters are supplied, the client certificate must satisfy both. Keep URL patterns as narrow as practical so a certificate intended for one service is not automatically offered to unrelated sites.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AutoSelectCertificateForUrls is supported on Windows and macOS from Edge 77, and on Android from Edge 147. It is not supported on iOS. The policy is per profile, supports dynamic refresh, and also applies to profiles signed in with a Microsoft account.

Handle multiple matching client certificates

The current policy is Prompt the user to select a certificate when multiple certificates match (PromptOnMultipleMatchingCertificates). Set it to enabled when users should choose explicitly whenever the automatic-selection rule matches more than one certificate.

On Windows, the registry value is:

PromptOnMultipleMatchingCertificates

It is a REG_DWORD; 0x00000001 enables prompting. The policy is supported on Windows and macOS from Edge 100, but not on Android or iOS. It is per profile and does not apply to a profile signed in with a Microsoft account.

When the policy is false or unset, Edge may prompt only when no certificate matches the automatic-selection policy. The older policy name ForceCertificatePromptsOnMultipleMatches is deprecated; use PromptOnMultipleMatchingCertificates in new configurations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Certificate Transparency exceptions

CertificateTransparencyEnforcementDisabledForUrls disables Certificate Transparency enforcement for listed hostnames. This is an exception policy, not a general certificate repair setting.

Only the hostname is considered. The scheme, port, and path are ignored, and wildcard hosts are not supported. Without the policy, a certificate that must be disclosed through Certificate Transparency can be treated as untrusted when it was not properly disclosed.

Disabling enforcement can make a previously untrusted certificate work, but it also permits certificates that would otherwise fail this check and makes mis-issued certificates harder to detect. Limit any exception to a documented hostname and remove it when the underlying certificate problem is fixed.

Troubleshoot a certificate problem systematically

  1. Identify the role. Decide whether the failure concerns the website’s server certificate or a client certificate requested by the server.
  2. Check the Edge version. The CA-management UI requires Edge 136 or later. Platform trust-store integration and other policies have separate minimum versions.
  3. Check policy status. Open edge://policy, select the option to reload policies if available, and inspect errors or conflicting values.
  4. Restart Edge. A Group Policy refresh does not always make an already-running browser reload every setting.
  5. Check the correct store and profile. A certificate in a different Windows store, user profile, browser profile, or device may not be available to the connection being tested.
  6. For mTLS, check the private key. A public certificate without its corresponding private key cannot normally authenticate the client.
  7. Check issuer and subject filters. An overly narrow AutoSelectCertificateForUrls rule can exclude the intended certificate; an overly broad rule can produce multiple matches.
  8. Check the server request. The server decides which client-certificate properties are acceptable. Edge cannot select a certificate that does not satisfy that request.
  9. Review exceptions. Do not add a Certificate Transparency exception or trust a new root merely to suppress an error without confirming the certificate’s origin.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

FAQ

Which Edge version includes certificate management for installed CA certificates?

The certificate-management experience is available starting with Microsoft Edge 136. The administrator policy is Allow users to manage installed CA certificates, with the registry name CACertificateManagementAllowed.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does CACertificateManagementAllowed set to 1 do?

Value 1, named UserOnly, allows users to manage user certificates. It does not allow them to change trust settings for built-in certificates.

Best Value
SAICOO smart Card Reader DOD Military USB Common Access CAC Card Reader, Compatible with Mac OS, Win (Horizontal Version)
  • DOD Military CAC USB Smart Card Reader for Government ID, National ID, ActivClient, AKO, OWA, DKO, JKO, NKO, BOL, GKO, Marinenet, AF Portal, Pure Edge Viewer, ApproveIt, DCO, DTS, LPS, Disa Enterprise Email etc. CAC Cards
  • Compatible with windows (32/64bit) XP/Vista/ 7/8/10, Mac OS X
  • Sleek Ergonomic Design -Gloss Black Finish. EMS ready.ISO7816 Class A,B and C.
  • What You Get: Saicoo CAC Smart Card Reader, 18-month warranty and lifetime technical support.

Why can I view certificates but not manage them in Edge?

An administrator may have set CACertificateManagementAllowed to 2 (None). That value disallows certificate management while still allowing users to view certificates. Check edge://policy.

Is AutoSelectCertificateForUrls used for trusted website certificates?

No. It controls automatic selection of client certificates when a server requests client authentication. CA certificate policies control trust in TLS server certificates.

What replaced ForceCertificatePromptsOnMultipleMatches?

The current policy is PromptOnMultipleMatchingCertificates. ForceCertificatePromptsOnMultipleMatches is deprecated and should not be used as the current setting.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I disable MicrosoftRootStoreEnabled to change certificate verification in current Edge?

No. MicrosoftRootStoreEnabled is obsolete and no longer controls certificate verification in current Edge. The policy was removed in stages through Edge 121 depending on platform.

Why does an installed CA certificate still not work?

Check the Edge version, the active browser profile, platform trust-store integration, policy conflicts, certificate validity and purpose, and whether the certificate was installed in the store Edge uses. Then verify the applied policies at edge://policy.

The Bottom Line

Manage CA trust and client authentication as separate systems. Use Edge’s certificate UI or CACertificateManagementAllowed for user control of installed CA certificates, Windows Group Policy for centrally deployed trust roots, CAPlatformIntegrationEnabled for platform-store integration, and AutoSelectCertificateForUrls for client-certificate selection. Verify every change at edge://policy, restart Edge after local policy changes, and avoid broad trust or Certificate Transparency exceptions unless they are deliberate and documented.

Quick Recap

SaleBestseller No. 1
Identiv SCR3310V2 USB Smart Card Reader Writer CAC/PIV
Identiv SCR3310V2 USB Smart Card Reader Writer CAC/PIV
Ergonomic and cost efficient design; Software and functionality compatible with SCM´s SCR33xx readers family
$12.99
Bestseller No. 2
ZOWEETEK CAC Card Reader Military, USB Smart Card Reader for Windows Mac
ZOWEETEK CAC Card Reader Military, USB Smart Card Reader for Windows Mac
Sleek ergonomic flat design, precise slot, convenient to horizontally plug card; Compatible with Windows10/11, Mac OS 10.15 or later. Driver free, plug and play.
$15.40
SaleBestseller No. 3
Identiv SCR3500 Smartfold Smart Card Reader
Identiv SCR3500 Smartfold Smart Card Reader
Compact And Lightweight Dongle Form-Factor Card Reader; Accepts Cards In Id1 Format (Iso8716)
$16.16
Bestseller No. 5
SAICOO smart Card Reader DOD Military USB Common Access CAC Card Reader, Compatible with Mac OS, Win (Horizontal Version)
SAICOO smart Card Reader DOD Military USB Common Access CAC Card Reader, Compatible with Mac OS, Win (Horizontal Version)
Compatible with windows (32/64bit) XP/Vista/ 7/8/10, Mac OS X; Sleek Ergonomic Design -Gloss Black Finish. EMS ready.ISO7816 Class A,B and C.
$14.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.