Loading...

Trust DigiCert Global Root G2 certificate authority to avoid Exchange Online email disruption

Trust DigiCert Global Root G2 certificate authority to avoid Exchange Online email disruption

To avoid Exchange Online email disruption by April 30, 2026, ensure your servers and clients trust the DigiCert Global Root G2 CA. This is critical if you disable Windows CTL updates or use older/custom runtimes. Windows systems with default CTL updates enabled require no action. Action might be required to avoid service disruption. To maintain secure and uninterrupted mail flow with Exchange Online, organizations must ensure their servers and clients trust the DigiCert Global Root G2 Certificate Authority (CA) and its subordinate CAs.  Organizations that rely on custom certificate trust stores, disabled Windows CTL updates, or older runtime environments might be impacted and may need to update their trusted certificate chains. When this will happen: Organizations must complete required certificate trust updates before April 30, 2026. How this affects your organization: Who is affected: This change applies to all organizations (Worldwide, GCC, GCC‑High, DoD) that: Send or receive email with Exchange Online and Either: Your organization has disabled the Windows CTL Updater feature that by default downloads the Certificate Trust List (CTL). The CTL contains trusted and untrusted root certificates. Learn more: Certificates and trust in Windows. This scenario may apply if your organization maintains its own set of trusted Root and Intermediate Certificates via Group Policy or via a redirected Microsoft Automatic Update URL. Learn more: Configure trusted roots and disallowed certificates in Windows. You can determine whether the Windows CTL Updater feature is disabled by reviewing the Who needs to take action section of this Microsoft guidance: Trust DigiCert Global Root G2 Certificate Authority to Avoid Exchange Online Email Disruption. You use older or custom application environments such as: Legacy Java/JDK/JRE runtimes Embedded systems and appliances Custom or outdated Linux images Air‑gapped systems Third‑party email gateways or security appliances that perform certificate chain validation This change applies to any system performing full certificate chain validation against Exchange Online, including Exchange Server, security appliances, and third-party email gateways. If you use third-party email appliances, please contact the vendor directly for support. Windows systems with the CTL Updater enabled (default) do not require action. What will happen: If the DigiCert Global […]

The post Trust DigiCert Global Root G2 certificate authority to avoid Exchange Online email disruption appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Trust DigiCert Global Root G2 certificate authority to avoid Exchange Online email disruption

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.