Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1193408

(Update)Action Required: Trust DigiCert Global Root G2 Certificate Authority for using Entra services by January 7, 2026

Plan for Change
Major Change

Message ID

MC1193408
View in Admin Center

Services

Microsoft Entra

Summary

By January 7, 2026, Microsoft Entra will switch from DigiCert Global Root G1 to G2 certificates. Organizations must trust the DigiCert G2 root CA to avoid authentication failures with Entra services. Remove any pinning to G1 and update trust settings to prevent service disruption.

Details

Updated December 12, 2025: We have updated the content. Thank you for your patience. 

Action Required: Trust the new DigiCert Certificate Authorities (CAs) for Microsoft Entra

Starting January 7, 2026, Microsoft Entra will migrate its DigiCert certificates from the G1 root CA to the G2 root CA. Clients that pin to the DigiCert G1 root or do not trust the DigiCert G2 root may experience authentication failures.

What are G1 and G2 root CAs?

Certificate Authorities (CAs) issue digital certificates that establish trust for secure communications. A root CA is the top-level certificate in a trust chain. DigiCert Global Root G1 is the current root CA used by Microsoft Entra services. DigiCert Global Root G2 is the newer root CA that Microsoft is migrating to for improved security and compliance. If your systems do not trust the G2 root, authentication and secure connections to Microsoft Entra services will fail.

Why you’re receiving this message:

Our reporting indicates that one or more users in your organization may be using Microsoft Entra ID.

When this will happen:

January 7, 2026.

How this affects your organization:
  • Who is affected: Organizations using Microsoft Entra ID services.
  • What will happen:
    • If DigiCert G2 certificates are not trusted, authentication failures will occur when accessing Microsoft Entra services.
    • Impacted domains include:
      • login.live.com
      • login.windows.net
      • autologon.microsoftazuread-sso.com
      • graph.windows.net
      • Note: The login.microsoftonline.com domain has already been migrated to the DigiCert G2 root in Feb 2025. Customers using this domain will not be impacted, as their client systems already trust DigiCert G2.
What you can do to prepare:
  • Trust all Root and Subordinate CAs listed in the Azure Certificate Authority details documentation.
  • Ensure you trust the “DigiCert Global Root G2” root and its subordinate CAs (documented since September 2025).
  • Remove any client-side pinning to the DigiCert Global Root CA root certificate.
  • Update your settings now to avoid service disruption.
Help and support:
  • For details about DigiCert certificates, refer to DigiCert documentation.
  • For guidance on issuer/certificate pinning, see Azure documentation.
  • Get answers from community experts in Microsoft Q&A.
  • If you have a support plan and need technical help, create a support request.
Compliance considerations:

No compliance considerations identified, review as appropriate for your organization.

Timeline

📅
Published
Dec 9, 2025
Message published to Message Center
✏️
Updated
Dec 12, 2025
Message content updated
⚠️
Action Required By
Jan 7, 2026
Action deadline
🏁
End Date
Feb 7, 2026
Message timeline ends

Tags

#Updated message#Admin impact

Category

📋Plan for Change

Related Messages

Similar updates

MC1179154

Microsoft Authenticator app: Upcoming changes to jailbreak and root detection

Oct 24, 2025
MC1198077

Microsoft Entra: Cross-tenant security group synchronization

Dec 16, 2025
MC1123830●

Microsoft Entra: Action Required – Update Conditional Access Policies for Azure DevOps Sign-ins

Jul 28, 2025
MC1097272●

Microsoft 365 Upcoming Secure by Default Settings Changes

Jun 17, 2025
MC1097225●

Entra ID: Upcoming changes to support passkey profiles in the authentication methods policy (preview)

Jun 17, 2025