Published Jan 30, 2026
To avoid Exchange Online email disruption by March 15, 2026, organizations must trust the DigiCert Global Root G2 certificate authority. This affects those with disabled Windows CTL updates or using older/custom runtimes. Systems with default Windows CTL Updater enabled require no action.
Updated February 4, 2026: We have updated the timeline. We’ve been notified that some email providers may distrust the DigiCert G1 root on April 15, which could result in broad ecosystem‑wide email impact. To ensure Exchange Online can rotate certificates ahead of this event, customers must trust the DigiCert Global Root G2 certificate authority by March 15 (previously April 30). Thank you for your patience.
Introduction
Action might be required to avoid service disruption. To maintain secure and uninterrupted mail flow with Exchange Online, organizations must ensure their servers and clients trust the DigiCert Global Root G2 Certificate Authority (CA) and its subordinate CAs.
Organizations that rely on custom certificate trust stores, disabled Windows CTL updates, or older runtime environments might be impacted and may need to update their trusted certificate chains.
When this will happen:
Organizations must complete required certificate trust updates before March 15, 2026 (previously April 30).
How this affects your organization:
Who is affected:
This change applies to all organizations (Worldwide, GCC, GCC‑High, DoD) that:
This change applies to any system performing full certificate chain validation against Exchange Online, including Exchange Server, security appliances, and third-party email gateways. If you use third-party email appliances, please contact the vendor directly for support.
Windows systems with the CTL Updater enabled (default) do not require action.
What will happen:
If the DigiCert Global Root G2 certificate or required intermediates are missing or cannot be retrieved during TLS negotiation:
If your organization already maintains the current Office 365 certificate chains, no impact is expected.
What you can do to prepare:
Required actions:
If your environment has disabled Windows CTL updates or relies on older/custom runtimes, complete the actions outlined in the What you must do section of: Trust DigiCert Global Root G2 Certificate Authority to Avoid Exchange Online Email Disruption
Specific actions include:
No action required if:
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.