A cloud-based identity and access management service for securing user authentication and resource access
Microsoft Azure RSA TLS Issuing CA 08 expiration and replacement certificate
Hello,
We are reviewing the certificates trusted by our SAP systems and noticed that the following intermediate CA is currently present in our SAP SSL trust store (STRUST):
Subject: Microsoft Azure RSA TLS Issuing CA 08
Issuer: DigiCert Global Root G2
Expiration Date: 25-Aug-2026
We also verified that DigiCert Global Root G2 is already present in the trust store and remains valid until 2038.
According to the Microsoft Entra Certificate Authority documentation, this CA is listed as one of the subordinate CAs used by Microsoft services.
Could Microsoft please clarify the following:
- Which certificate will replace Microsoft Azure RSA TLS Issuing CA 08 after its expiration?
- Is the replacement certificate already published and available for download?
- Does Microsoft provide advance notification of such CA transitions?
- Will the replacement certificate continue to chain to DigiCert Global Root G2?
- Is any action required for customers maintaining custom trust stores, such as SAP STRUST, before 25-Aug-2026?
We are asking this question proactively to ensure there is no impact to SAP integrations relying on Microsoft services.
Thank you.