en-US edge computer user

Check RSA key usage for server certificates issued by local trust anchors (obsolete)

Verified with Microsoft Edge 152.0.4191.53 — updated on July 10, 2026

Microsoft Edge 152.0.4191.53

Supported on: Microsoft Edge version 123-135, Windows 7 or later

Path in the GPO console

Computer Configuration\Administrative Templates\Microsoft Edge

Description

OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 135. The X.509 key usage extension declares how the key in a certificate can be used. These instructions ensure certificates aren't used in an unintended context, which protects against a class of cross-protocol attacks on HTTPS and other protocols. HTTPS clients must verify that server certificates match the connection's TLS parameters. Starting in Microsoft Edge 124, this check is always enabled. Microsoft Edge 123 and earlier have the following behavior: If this policy is set to enabled, Microsoft Edge performs this key check. This helps prevent attacks where an attacker manipulates the browser into interpreting a key in ways that the certificate owner didn't intend. If this policy is set to disabled, Microsoft Edge skips this key check-in HTTPS connections that negotiate TLS 1.2 and use an RSA certificate that chains to a local trust anchor. Examples of local trust anchors include policy-provided or user-installed root certificates. In all other cases, the check is performed independent of this policy's setting. If this policy isn't configured, Microsoft Edge behaves as if the policy is enabled. This policy is available for administrators to preview the behavior of a future release, which will enable this check by default. At that point, this policy will remain temporarily available for administrators that need more time to update their certificates to meet the new RSA key usage requirements. Connections that fail this check will fail with the error ERR_SSL_KEY_USAGE_INCOMPATIBLE. Sites that fail with this error likely have a misconfigured certificate. Modern ECDHE_RSA cipher suites use the "digitalSignature" key usage option, while legacy RSA decryption cipher suites use the "keyEncipherment" key usage option. If uncertain, administrators should include both in RSA certificates meant for HTTPS. The policy has been obsoleted starting from Microsoft Edge version 136, but the key check has been always enabled since Microsoft Edge version 124.

Registry

HKLM Software\Policies\Microsoft\Edge
HKCU Software\Policies\Microsoft\Edge

Value name: RSAKeyUsageForLocalAnchorsEnabled

Enabled: RSAKeyUsageForLocalAnchorsEnabled = 1

Disabled: RSAKeyUsageForLocalAnchorsEnabled = 0

Export Builder

BETA

Configure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.

These exports write the registry — this is not a managed GPO.

Scope

.reg file

Windows Registry Editor Version 5.00

; Exported from gporais.com
; Policy: Check RSA key usage for server certificates issued by local trust anchors (obsolete)
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Edge version 123-135, Windows 7 or later

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge]
"RSAKeyUsageForLocalAnchorsEnabled"=dword:00000001
More formats (PowerShell, Intune, SCCM)

PowerShell

# Exported from gporais.com
# Policy: Check RSA key usage for server certificates issued by local trust anchors (obsolete)
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 123-135, Windows 7 or later

$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'RSAKeyUsageForLocalAnchorsEnabled' -Value 1 -Type DWord

Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.

Open the Builder

Embed this policy on your site

What to embed
Theme

Adds one script line: the theme follows your site’s appearance and the height fits the content. If your site blocks scripts, the embed follows the visitor’s system theme.

Preview