Check RSA key usage for server certificates issued by local trust anchors (obsolete)
Verified with Microsoft Edge 152.0.4191.53 — updated on July 10, 2026
Supported on: Microsoft Edge version 123-135, Windows 7 or later
Path in the GPO console
Computer Configuration\Administrative Templates\Microsoft Edge User Configuration\Administrative Templates\Microsoft Edge Description
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 135. The X.509 key usage extension declares how the key in a certificate can be used. These instructions ensure certificates aren't used in an unintended context, which protects against a class of cross-protocol attacks on HTTPS and other protocols. HTTPS clients must verify that server certificates match the connection's TLS parameters. Starting in Microsoft Edge 124, this check is always enabled. Microsoft Edge 123 and earlier have the following behavior: If this policy is set to enabled, Microsoft Edge performs this key check. This helps prevent attacks where an attacker manipulates the browser into interpreting a key in ways that the certificate owner didn't intend. If this policy is set to disabled, Microsoft Edge skips this key check-in HTTPS connections that negotiate TLS 1.2 and use an RSA certificate that chains to a local trust anchor. Examples of local trust anchors include policy-provided or user-installed root certificates. In all other cases, the check is performed independent of this policy's setting. If this policy isn't configured, Microsoft Edge behaves as if the policy is enabled. This policy is available for administrators to preview the behavior of a future release, which will enable this check by default. At that point, this policy will remain temporarily available for administrators that need more time to update their certificates to meet the new RSA key usage requirements. Connections that fail this check will fail with the error ERR_SSL_KEY_USAGE_INCOMPATIBLE. Sites that fail with this error likely have a misconfigured certificate. Modern ECDHE_RSA cipher suites use the "digitalSignature" key usage option, while legacy RSA decryption cipher suites use the "keyEncipherment" key usage option. If uncertain, administrators should include both in RSA certificates meant for HTTPS. The policy has been obsoleted starting from Microsoft Edge version 136, but the key check has been always enabled since Microsoft Edge version 124.
Registry
Software\Policies\Microsoft\Edge Software\Policies\Microsoft\Edge Value name: RSAKeyUsageForLocalAnchorsEnabled
Enabled: RSAKeyUsageForLocalAnchorsEnabled = 1
Disabled: RSAKeyUsageForLocalAnchorsEnabled = 0
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
Applying both scopes creates an ambiguous configuration (computer takes precedence over user). Only do this intentionally.
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Check RSA key usage for server certificates issued by local trust anchors (obsolete)
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Edge version 123-135, Windows 7 or later
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge]
"RSAKeyUsageForLocalAnchorsEnabled"=dword:00000001 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Check RSA key usage for server certificates issued by local trust anchors (obsolete)
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 123-135, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'RSAKeyUsageForLocalAnchorsEnabled' -Value 1 -Type DWord Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Check RSA key usage for server certificates issued by local trust anchors (obsolete)
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 123-135, Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Edge' -Name 'RSAKeyUsageForLocalAnchorsEnabled' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Check RSA key usage for server certificates issued by local trust anchors (obsolete)
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 123-135, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'RSAKeyUsageForLocalAnchorsEnabled' -Value 1 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Check RSA key usage for server certificates issued by local trust anchors (obsolete)
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 123-135, Windows 7 or later
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Check RSA key usage for server certificates issued by local trust anchors (obsolete)
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 123-135, Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Edge' -Name 'RSAKeyUsageForLocalAnchorsEnabled' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Check RSA key usage for server certificates issued by local trust anchors (obsolete)
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 123-135, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'RSAKeyUsageForLocalAnchorsEnabled' -Value 1 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.