iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Microsoft Edge uses certificates for two different jobs that are easy to confuse:
- CA certificates establish whether a website’s TLS certificate can be trusted.
- Client certificates identify the browser to a server when a site requires mutual TLS (mTLS).
Edge’s certificate-management experience for installed CA certificates is available starting with Edge 136. Administrators can control it with policy, while Windows domain administrators can continue deploying certificates through Windows Group Policy. Client-certificate selection is controlled separately.
What Edge certificates do
When you open an HTTPS site, Edge validates the server’s certificate chain. It checks the certificate’s signature, validity dates, hostname, revocation-related requirements, and whether the issuing chain leads to a trusted CA. A private key normally stays with the certificate owner and is used to prove possession when needed; it should not be exported or shared casually.
Recommended Free Tools
There are two important certificate categories:
| Certificate type | Used for | Relevant Edge controls |
|---|---|---|
| CA or server-trust certificate | Deciding whether a website’s TLS certificate is trusted | CACertificateManagementAllowed, CACertificates, CACertificatesWithConstraints, CADistrustedCertificates, CAHintCertificates |
| Client certificate | Authenticating the browser or user to a server requesting client authentication | AutoSelectCertificateForUrls, PromptOnMultipleMatchingCertificates |
Installing a CA certificate will not make Edge automatically choose a client certificate, and configuring automatic client-certificate selection will not make an untrusted website certificate trusted.
#1 Best Overall
- Fully Compliant - Complies With All Major Industry Standards, Including Iso/Iec 7816, Usb Ccid, Pc/Sc, And Microsoft Whql. As Well As, Emv 2011 Ver 4.3 Level 1 And Gsa Fips 201.
- Seamless Integration - With Identiv-Specific Smartos You’Ll Get Easy, Complete Support Of All Major Contact Smart Card Ics And Technologies In One Simple Reader.
- Universal Compatibility - Works With Virtually All Contact Chip Cards And Pc Operating Systems, Including Windows, Macos, Linux And Android.
- Fast And Convenient- Shorten Your Transaction Time With A Reader That’S Optimized For Speed. It’S Ultra-Compact And Robust Design Is Streamlined For Mobile Operation, Making This Reader The Best Choice For Convenience, Security And Reliability.
- Ergonomic and cost efficient design
Manage installed CA certificates in Edge
On Edge 136 and later, open Edge’s Settings and search for certificate or manage certificates. The certificate-management page is available through the browser’s privacy and security settings. The exact label and layout can vary by Edge release and operating system.
- Open Microsoft Edge.
- Open
edge://settings. - Use the Settings search box and search for certificate.
- Open the certificate-management option shown by your installation.
- Review the installed CA certificates and use the available management action, such as adding or removing a certificate, only when you understand which trust decisions it changes.
If the management controls are missing or disabled, the browser may be managed by an administrator. The policy controlling this experience is Allow users to manage installed CA certificates (CACertificateManagementAllowed).
Certificate-management policy values
| Value | Name | Effect |
|---|---|---|
0 |
All | Users can manage all certificates. |
1 |
UserOnly | Users can manage user certificates. Trust settings for built-in certificates cannot be changed. |
2 |
None | Users cannot manage certificates, although they can view them. |
This policy is per profile, but it does not apply to a profile signed in with a Microsoft account. It is supported from Edge 136.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Control certificate management with Group Policy
On Windows, install the current Microsoft Edge administrative templates, then open the Group Policy editor and go to:
Computer Configuration or User Configuration
> Policies
> Administrative Templates
> Microsoft Edge
> Certificate management settings
- Open Allow users to manage installed CA certificates.
- Select Enabled.
- Choose the required value: All, UserOnly, or None.
- Apply the policy and refresh Group Policy.
- Close and reopen Edge before testing the browser UI.
Force a refresh from Command Prompt or PowerShell with:
gpupdate /force
Check what Edge actually received by opening:
edge://policy
Look for CACertificateManagementAllowed and confirm that the expected value is shown. A policy can be correctly configured in Group Policy but still appear unchanged in Edge until the browser is restarted.
Set the policy through the registry
For a computer-level policy, the registry location is:
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #2
- Advanced Realtek Chipset; PIV, EMS, ISO-7816 & EMV2 2000 Level 1, CE, FCC, VCCI and Microsoft WHQL certifications.
- Supports ActivClient, AKO, OWA, DKO, JKO, NKO, BOL, GKO, Marinenet, AF Portal, Pure Edge Viewer, ApproveIt, DCO, DTS, LPS, Disa Enterprise Email and etc. CAC chip cards
- Sleek ergonomic flat design, precise slot, convenient to horizontally plug card
- Compatible with Windows10/11, Mac OS 10.15 or later. Driver free, plug and play.
- New generation DOD Military CAC USB smart chip card reader, no firmware upgrade requirements
HKLMSOFTWAREPoliciesMicrosoftEdge
Create or modify this value:
Name: CACertificateManagementAllowed
Type: REG_DWORD
Example: 0x00000001
For example, this command allows users to manage user certificates only:
reg add "HKLMSOFTWAREPoliciesMicrosoftEdge" /v CACertificateManagementAllowed /t REG_DWORD /d 1 /f
After changing it, run gpupdate /force if appropriate, restart Edge, and verify the result at edge://policy. Registry policy changes should be made through your organization’s configuration process rather than manually on production machines.
Deploy certificates through Windows instead of the Edge UI
Edge’s certificate-management UI is not a replacement for enterprise certificate deployment. Windows domain administrators can deploy certificates with Group Policy from:
Computer Configuration
> Policies
> Windows Settings
> Security Settings
> Public Key Policies
- Open the target certificate store, such as Trusted Root Certification Authorities.
- Right-click the store and select Import.
- Choose the certificate file and complete the Certificate Import Wizard.
- Link the Group Policy Object to the computers or users that need the certificate.
Use a trusted root only when you intentionally want the issuing CA to trust server certificates. Adding a company inspection CA, lab CA, or self-signed root broadly can allow that CA to intercept or impersonate TLS connections.
Use certificates from the operating system trust store
The policy Use user-added TLS certificates from platform trust stores for server authentication (CAPlatformIntegrationEnabled) controls whether user-added certificates from the operating system’s platform trust store participate in TLS server-certificate path building.
- Enabled or unset: user-added platform certificates are used.
- Disabled: they are not used.
On Windows and macOS, this policy is supported from Edge 133. Android support begins with Edge 138; iOS does not support this policy.
Its Windows Group Policy location is:
Administrative Templates
> Microsoft Edge
> Certificate management settings
The Windows registry value is:
CAPlatformIntegrationEnabled
It is a REG_DWORD; 0x00000000 disables platform integration. For example:
Rank #3
- Compact And Lightweight Dongle Form-Factor Card Reader
- Accepts Cards In Id1 Format (Iso8716)
- Ccid Compliant
- Compact and lightweight dongle form-factor card reader
- Accepts cards in ID1 format (ISO8716)
reg add "HKLMSOFTWAREPoliciesMicrosoftEdge" /v CAPlatformIntegrationEnabled /t REG_DWORD /d 0 /f
Do not use the old MicrosoftRootStoreEnabled advice found in older troubleshooting guides. That policy was removed from current Edge: Windows and macOS in Edge 115, Linux in Edge 120, and Android in Edge 121. It no longer controls certificate verification in current Edge.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Configure automatic client-certificate selection
A server using mTLS sends a certificate request to Edge. The browser then needs to choose an eligible client certificate, usually one with a private key. The policy for automating that choice is AutoSelectCertificateForUrls.
The policy is a list of strings. Each string contains a stringified JSON dictionary with a URL pattern and a filter:
{
"pattern": "https://example.com",
"filter": {
"ISSUER": {
"CN": "Example Issuing CA"
}
}
}
The ISSUER.CN filter limits selection to certificates issued by a CA with that Common Name. Edge still considers the server’s certificate request: a certificate that does not match what the server requests is not eligible, even if it matches the configured filter.
If both ISSUER and SUBJECT filters are supplied, the client certificate must satisfy both. Keep URL patterns as narrow as practical so a certificate intended for one service is not automatically offered to unrelated sites.
AutoSelectCertificateForUrls is supported on Windows and macOS from Edge 77, and on Android from Edge 147. It is not supported on iOS. The policy is per profile, supports dynamic refresh, and also applies to profiles signed in with a Microsoft account.
Handle multiple matching client certificates
The current policy is Prompt the user to select a certificate when multiple certificates match (PromptOnMultipleMatchingCertificates). Set it to enabled when users should choose explicitly whenever the automatic-selection rule matches more than one certificate.
Rank #4
On Windows, the registry value is:
PromptOnMultipleMatchingCertificates
It is a REG_DWORD; 0x00000001 enables prompting. The policy is supported on Windows and macOS from Edge 100, but not on Android or iOS. It is per profile and does not apply to a profile signed in with a Microsoft account.
When the policy is false or unset, Edge may prompt only when no certificate matches the automatic-selection policy. The older policy name ForceCertificatePromptsOnMultipleMatches is deprecated; use PromptOnMultipleMatchingCertificates in new configurations.
Certificate Transparency exceptions
CertificateTransparencyEnforcementDisabledForUrls disables Certificate Transparency enforcement for listed hostnames. This is an exception policy, not a general certificate repair setting.
Only the hostname is considered. The scheme, port, and path are ignored, and wildcard hosts are not supported. Without the policy, a certificate that must be disclosed through Certificate Transparency can be treated as untrusted when it was not properly disclosed.
Disabling enforcement can make a previously untrusted certificate work, but it also permits certificates that would otherwise fail this check and makes mis-issued certificates harder to detect. Limit any exception to a documented hostname and remove it when the underlying certificate problem is fixed.
Troubleshoot a certificate problem systematically
- Identify the role. Decide whether the failure concerns the website’s server certificate or a client certificate requested by the server.
- Check the Edge version. The CA-management UI requires Edge 136 or later. Platform trust-store integration and other policies have separate minimum versions.
- Check policy status. Open
edge://policy, select the option to reload policies if available, and inspect errors or conflicting values. - Restart Edge. A Group Policy refresh does not always make an already-running browser reload every setting.
- Check the correct store and profile. A certificate in a different Windows store, user profile, browser profile, or device may not be available to the connection being tested.
- For mTLS, check the private key. A public certificate without its corresponding private key cannot normally authenticate the client.
- Check issuer and subject filters. An overly narrow
AutoSelectCertificateForUrlsrule can exclude the intended certificate; an overly broad rule can produce multiple matches. - Check the server request. The server decides which client-certificate properties are acceptable. Edge cannot select a certificate that does not satisfy that request.
- Review exceptions. Do not add a Certificate Transparency exception or trust a new root merely to suppress an error without confirming the certificate’s origin.
FAQ
Which Edge version includes certificate management for installed CA certificates?
The certificate-management experience is available starting with Microsoft Edge 136. The administrator policy is Allow users to manage installed CA certificates, with the registry name CACertificateManagementAllowed.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What does CACertificateManagementAllowed set to 1 do?
Value 1, named UserOnly, allows users to manage user certificates. It does not allow them to change trust settings for built-in certificates.
Best Value
- DOD Military CAC USB Smart Card Reader for Government ID, National ID, ActivClient, AKO, OWA, DKO, JKO, NKO, BOL, GKO, Marinenet, AF Portal, Pure Edge Viewer, ApproveIt, DCO, DTS, LPS, Disa Enterprise Email etc. CAC Cards
- Compatible with windows (32/64bit) XP/Vista/ 7/8/10, Mac OS X
- Sleek Ergonomic Design -Gloss Black Finish. EMS ready.ISO7816 Class A,B and C.
- What You Get: Saicoo CAC Smart Card Reader, 18-month warranty and lifetime technical support.
Why can I view certificates but not manage them in Edge?
An administrator may have set CACertificateManagementAllowed to 2 (None). That value disallows certificate management while still allowing users to view certificates. Check edge://policy.
Is AutoSelectCertificateForUrls used for trusted website certificates?
No. It controls automatic selection of client certificates when a server requests client authentication. CA certificate policies control trust in TLS server certificates.
What replaced ForceCertificatePromptsOnMultipleMatches?
The current policy is PromptOnMultipleMatchingCertificates. ForceCertificatePromptsOnMultipleMatches is deprecated and should not be used as the current setting.
Free tools Windows power users keep installed
One-click scans. No signup required.
Can I disable MicrosoftRootStoreEnabled to change certificate verification in current Edge?
No. MicrosoftRootStoreEnabled is obsolete and no longer controls certificate verification in current Edge. The policy was removed in stages through Edge 121 depending on platform.
Why does an installed CA certificate still not work?
Check the Edge version, the active browser profile, platform trust-store integration, policy conflicts, certificate validity and purpose, and whether the certificate was installed in the store Edge uses. Then verify the applied policies at edge://policy.
The Bottom Line
Manage CA trust and client authentication as separate systems. Use Edge’s certificate UI or CACertificateManagementAllowed for user control of installed CA certificates, Windows Group Policy for centrally deployed trust roots, CAPlatformIntegrationEnabled for platform-store integration, and AutoSelectCertificateForUrls for client-certificate selection. Verify every change at edge://policy, restart Edge after local policy changes, and avoid broad trust or Certificate Transparency exceptions unless they are deliberate and documented.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

