Loading...

Action Required: Trust DigiCert Global Root G2 Certificate Authority for using Entra services by January 7, 2026

Action Required: Trust DigiCert Global Root G2 Certificate Authority for using Entra services by January 7, 2026

By January 7, 2026, Microsoft Entra will switch from DigiCert Global Root G1 to G2 certificates. Organizations must trust the DigiCert G2 root CA to avoid authentication failures with Entra services and remove any client-side pinning to the G1 root. Update settings to prevent disruption. Action Required: Trust the new DigiCert Certificate Authorities (CAs) for Microsoft Entra Starting January 7, 2026, Microsoft Entra will migrate its DigiCert certificates from the G1 root CA to the G2 root CA. Clients that pin to the DigiCert G1 root or do not trust the DigiCert G2 root may experience authentication failures. What are G1 and G2 root CAs? Certificate Authorities (CAs) issue digital certificates that establish trust for secure communications. A root CA is the top-level certificate in a trust chain. DigiCert Global Root G1 is the current root CA used by Microsoft Entra services. DigiCert Global Root G2 is the newer root CA that Microsoft is migrating to for improved security and compliance. If your systems do not trust the G2 root, authentication and secure connections to Microsoft Entra services will fail. Why you’re receiving this message: Our reporting indicates that one or more users in your organization may be using Microsoft Entra ID. When this will happen: January 7, 2026. How this affects your organization: Who is affected: Organizations using Microsoft Entra ID services. What will happen: If DigiCert G2 certificates are not trusted, authentication failures will occur when accessing Microsoft Entra services. Impacted domains include: login.microsoftonline.com login.live.com login.windows.net autologon.microsoftazuread-sso.com graph.windows.net What you can do to prepare:Help and support:Compliance considerations: No compliance considerations identified, review as appropriate for your organization. Trust all Root and Subordinate CAs listed in the Azure Certificate Authority details documentation. Ensure you trust the “DigiCert Global Root G2” root and its subordinate CAs (documented since September 2025). Remove any client-side pinning to the DigiCert Global Root CA root certificate. Update your settings now to avoid service disruption. For details about DigiCert certificates, refer to DigiCert documentation. For guidance on issuer/certificate pinning, see Azure documentation. Get answers from community experts in Microsoft Q&A. If you have a support plan […]

The post Action Required: Trust DigiCert Global Root G2 Certificate Authority for using Entra services by January 7, 2026 appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Action Required: Trust DigiCert Global Root G2 Certificate Authority for using Entra services by January 7, 2026

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Excel: Excel canvas

Excel canvas, a new Copilot feature in Microsoft Excel, creates dynamic reports with visualizations and insights that update automatically wit...

2 days ago

Dynamics 365 Contact Center – Use role-based enforcement for recording and transcription downloads

We are announcing the ability to use role-based enforcement for recording and transcription downloads in Dynamics 365 Contact Center. This fea...

2 days ago

Microsoft Outlook: Right-click to customize the classic ribbon

Microsoft Outlook now allows users to customize the classic ribbon by right-clicking on the Home or View tab to select commands and arrange th...

2 days ago

Microsoft Exchange Online: Exchange Web Services (EWS) enforcement update for EWSAllowedAppIDs

Starting October 10, 2026, Exchange Online tenants must configure EWSAllowedAppIDs to allow Exchange Web Services (EWS) access; EWSEnabled=Tru...

2 days ago

Microsoft Entra App Gallery: Self-service onboarding for new applications

Microsoft Entra App Gallery introduces self-service onboarding for new applications, allowing ISVs to validate SSO and provisioning integratio...

2 days ago

Upgraded call history in Teams Calls app

Teams Calls app call history is upgraded to consolidate missed calls and voicemails into single entries and expand history from 100 to 3,000 r...

2 days ago

Power Automate – Enable Process Intelligence Studio in object-centric process mining

We are announcing the availability of Process Intelligence Studio in object-centric process mining in Power Automate Process Mining. This feat...

2 days ago

Dynamics 365 Contact Center – Use after conversation presence status for wrap-up activities

We are announcing the ability to use after conversation presence status for wrap-up activities in Dynamics 365 Contact Center. This feature wi...

2 days ago

Dynamics 365 Finance and Operations cross-app: Migrate finance and operations environments from Lifecycle Services to Power Platform admin center

The self-service environment migration feature moves management of an existing finance and operations apps environment from Microsoft Dynamics...

2 days ago

Microsoft Teams: Start side conversations during meetings

Keep collaboration moving without disrupting the main discussion. Start and continue one-to-one or small-group conversations directly from a m...

2 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.