Microsoft Entra certificate-based authentication (CBA) issuer hints help compatible browsers and native apps show a more relevant set of certificates during sign-in. Entra sends trusted certificate-authority (CA) information during the TLS handshake; clients that support the feature can use it to filter the certificate picker. Issuer hints guide selection—they do not issue certificates or replace your organization’s PKI.
What issuer hints change during sign-in
When a user has multiple certificates available, choosing the right one can be confusing. Microsoft says a compatible browser or native application can use the hints returned by the server to filter the certificates shown in its picker. The result is a shorter, more focused choice when the client supports filtering and the user has certificates from multiple issuers. The exact picker experience depends on the client; issuer hints do not guarantee that every client will display or filter certificates in the same way.
The hints identify trusted issuers using CA subjects in the tenant’s Entra trust store. They are part of certificate selection in CBA, not a replacement for certificate validation, CA trust, or the organization’s certificate issuance and lifecycle processes. Microsoft’s technical overview of certificate-based authentication explains how the trust store and hints fit into the sign-in flow.
How Entra determines which issuers to send
Microsoft documents more than one administrative control, so distinguish the setting you are changing from the behavior of the trust store:
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Per-CA selection in the PKI-based trust-store setup: The CA’s
isIssuerHintEnabledattribute controls whether its subject is returned as a hint. Microsoft’s setup guidance says subjects are sent by default in this configuration path and recommends setting the attribute totrueonly for CAs that issue user certificates. This helps avoid advertising unrelated issuers. - Issuer-hints configuration state: The Microsoft Graph v1.0 resource separately describes issuer-hints configuration as enabled or disabled. Treat that state as distinct from the per-CA attribute; do not assume that changing one control automatically configures the other.
- Global or selected-CA configuration: Microsoft’s setup options allow hints to be enabled globally or selected by CA, depending on the setup path. Choose the control that matches the trust-store configuration you are using.
For the current setup steps and their applicable admin surface, use Microsoft’s issuer-hints configuration guide. For the Graph resource definition, see Microsoft Graph’s certificateBasedAuthConfiguration resource.
Configuration limits and propagation time
Plan the issuer list and network path before enabling the feature. Microsoft’s setup documentation states that the server response for issuer hints is limited to 16 KB. In its PKI-based trust-store documentation, Microsoft also lists a limit of 250 CAs and 8 KB per CA object. These are product limits, not recommended targets; include only the CA subjects users need for authentication.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
After a CA is added to, updated in, or deleted from the trust store, changes to issuer hints can take up to 10 minutes to propagate, according to Microsoft’s technical-concepts documentation. Once hints are available, an Authentication Policy Administrator should sign in using a certificate to initiate propagation. Allow for that process before diagnosing a recently changed trust store as a client-side failure.
Make the certificate-authentication endpoint reachable
Issuer hints depend on access to the certificate-authentication endpoint for the tenant’s cloud environment. Microsoft identifies certauth.login.microsoftonline.com for the public Microsoft Entra cloud and documents corresponding endpoints for government clouds. Confirm the endpoint for your environment in Microsoft’s current setup documentation rather than applying the public-cloud hostname to every tenant.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
If your organization uses TLS inspection, Microsoft advises disabling it for the relevant certificate-authentication endpoint. Inspection or network filtering that interferes with the endpoint can prevent the expected certificate-authentication behavior. Review the environment-specific requirements in the issuer-hints setup guide before changing proxy or inspection rules.
Trust-store setup and licensing distinction
The PKI-based trust store uses CA material managed in PKI containers. Microsoft’s setup page says its PKI upload feature requires Microsoft Entra ID P1 or P2. Administrators using the free license can upload CA files individually and then add them to the trust store. That upload-path requirement is separate from the feature’s overall status: Microsoft describes Entra CBA itself as free. Check the current licensing and setup guidance for the specific method you plan to use.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Issuer hints do not create or manage your CA hierarchy, issue user certificates, or take over certificate lifecycle tasks. Your organization still needs to configure trusted CAs appropriately and manage certificate issuance and lifecycle, including the operational processes on which its PKI depends.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Important scenario limitation
Microsoft’s limitations documentation says CA hints are not supported for the documented CBA-without-federation scenario. That limitation applies to that scenario; it should not be read as a blanket statement that issuer hints are unavailable in the supported issuer-hints setup. Check the scenario and configuration path described by the relevant Microsoft documentation before relying on hints.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Best Value
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
For that caveat, see Microsoft’s CBA limitations documentation. For the feature’s configuration requirements, use the current issuer-hints setup documentation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

