Trust DigiCert Global Root G2 certificate authority to avoid Exchange Online email disruption
To avoid Exchange Online email disruption by April 30, 2026, ensure your servers and clients trust the DigiCert Global Root G2 CA. This is critical if you disable Windows CTL updates or use older/custom runtimes. Windows systems with default CTL updates enabled require no action. Action might be required to avoid service disruption. To maintain secure and uninterrupted mail flow with Exchange Online, organizations must ensure their servers and clients trust the DigiCert Global Root G2 Certificate Authority (CA) and its subordinate CAs. Organizations that rely on custom certificate trust stores, disabled Windows CTL updates, or older runtime environments might be impacted and may need to update their trusted certificate chains. When this will happen: Organizations must complete required certificate trust updates before April 30, 2026. How this affects your organization: Who is affected: This change applies to all organizations (Worldwide, GCC, GCC‑High, DoD) that: Send or receive email with Exchange Online and Either: Your organization has disabled the Windows CTL Updater feature that by default downloads the Certificate Trust List (CTL). The CTL contains trusted and untrusted root certificates. Learn more: Certificates and trust in Windows. This scenario may apply if your organization maintains its own set of trusted Root and Intermediate Certificates via Group Policy or via a redirected Microsoft Automatic Update URL. Learn more: Configure trusted roots and disallowed certificates in Windows. You can determine whether the Windows CTL Updater feature is disabled by reviewing the Who needs to take action section of this Microsoft guidance: Trust DigiCert Global Root G2 Certificate Authority to Avoid Exchange Online Email Disruption. You use older or custom application environments such as: Legacy Java/JDK/JRE runtimes Embedded systems and appliances Custom or outdated Linux images Air‑gapped systems Third‑party email gateways or security appliances that perform certificate chain validation This change applies to any system performing full certificate chain validation against Exchange Online, including Exchange Server, security appliances, and third-party email gateways. If you use third-party email appliances, please contact the vendor directly for support. Windows systems with the CTL Updater enabled (default) do not require action. What will happen: If the DigiCert Global […]
The post Trust DigiCert Global Root G2 certificate authority to avoid Exchange Online email disruption appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Trust DigiCert Global Root G2 certificate authority to avoid Exchange Online email disruption
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
OneDrive Photos on Windows: admin controls and policy support
OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...
Admin app retiring in Teams, Outlook and Microsoft365.com
The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...
Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting
Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...
Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices
The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...
Outlook for iOS: Minimum system requirements updated to iOS 26 and above
Outlook for iOS will require iOS 26 or later starting mid-September 2026, supporting only the two latest iOS, iPadOS, and watchOS versions. Us...
Allow connections to copilot.cloud.microsoft before the Copilot URL redirect
Starting September 2026, Microsoft will redirect users from m365.cloud.microsoft to copilot.cloud.microsoft. Organizations must ensure network...
Prepare for the removal of WMIC from Windows 11
The Windows Management Instrumentation command-line (WMIC) utility has been removed from Windows 11, version 24H2 and later. It’s no longer av...
Microsoft Agent 365: Active Users export for agent usage reporting
Microsoft Agent 365 will add an Active Users export in the Microsoft 365 admin center, allowing AI and Global Admins to generate a CSV report ...
The August 2026 Windows non-security preview update is now available
The August 2026 non-security preview update is now available for Windows 11, versions 26H1, 25H2, and 24H2. Information about the contents of ...
Dynamics 365 Project Operations – Assign task level schedule mode for precise planning
We are announcing the ability to assign task level schedule mode for precise planning in Dynamics 365 Project Operations. This feature will re...