Disable Certificate Transparency enforcement for a list of legacy certificate authorities (obsolete)
Verified with Microsoft Edge 152.0.4191.53 — updated on July 10, 2026
Supported on: Microsoft Edge version 77-131, Windows 7 or later
Path in the GPO console
Computer Configuration\Administrative Templates\Microsoft Edge User Configuration\Administrative Templates\Microsoft Edge Description
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 131. Disables enforcing Certificate Transparency requirements for a list of legacy certificate authorities (Cas). This policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This disablement of requirements allows otherwise-untrusted certificates (on account of not being publicly disclosed) to continue to be used for enterprise hosts. For Certificate Transparency enforcement to be disabled, you must set the hash to a subjectPublicKeyInfo appearing in an authority-issued certificate that's recognized as a legacy certificate authority (CA). A legacy CA is a CA publicly trusted, by default, by one or more operating systems supported by Microsoft Edge. You specify a subjectPublicKeyInfo hash by concatenating the hash algorithm name, the "/" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is "sha256". If you don't configure this policy, any certificate that's required to be disclosed via Certificate Transparency is treated as untrusted if it isn't disclosed according to the Certificate Transparency policy. This policy is obsolete because the feature to disable Certificate Transparency enforcement for legacy certificates has been removed. Example value: sha256/AAAAAAAAAAAAAAAAAAAAAA== sha256//////////////////////w==
Registry
Software\Policies\Microsoft\Edge Software\Policies\Microsoft\Edge Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
Applying both scopes creates an ambiguous configuration (computer takes precedence over user). Only do this intentionally.
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Disable Certificate Transparency enforcement for a list of legacy certificate authorities (obsolete)
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Edge version 77-131, Windows 7 or later
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge\CertificateTransparencyEnforcementDisabledForLegacyCas]
; List values: enter one value per line in the builder UI. More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Disable Certificate Transparency enforcement for a list of legacy certificate authorities (obsolete)
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 77-131, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge\CertificateTransparencyEnforcementDisabledForLegacyCas'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Disable Certificate Transparency enforcement for a list of legacy certificate authorities (obsolete)
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 77-131, Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
# HKLM:\Software\Policies\Microsoft\Edge\CertificateTransparencyEnforcementDisabledForLegacyCas: List values: enter one value per line in the builder UI.
# No testable registry values are available for this state.
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Disable Certificate Transparency enforcement for a list of legacy certificate authorities (obsolete)
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 77-131, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge\CertificateTransparencyEnforcementDisabledForLegacyCas'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. SCCM scripts
# Exported from gporais.com
# Policy: Disable Certificate Transparency enforcement for a list of legacy certificate authorities (obsolete)
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 77-131, Windows 7 or later
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Disable Certificate Transparency enforcement for a list of legacy certificate authorities (obsolete)
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 77-131, Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
# HKLM:\Software\Policies\Microsoft\Edge\CertificateTransparencyEnforcementDisabledForLegacyCas: List values: enter one value per line in the builder UI.
# No testable registry values are available for this state.
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Disable Certificate Transparency enforcement for a list of legacy certificate authorities (obsolete)
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 77-131, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge\CertificateTransparencyEnforcementDisabledForLegacyCas'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.