Microsoft Azure RSA TLS Issuing CA 08 expiration and replacement certificate

Gaspar, Pedro 10 Reputation points
2026-08-10T11:49:16.9266667+00:00

Hello,

We are reviewing the certificates trusted by our SAP systems and noticed that the following intermediate CA is currently present in our SAP SSL trust store (STRUST):

Subject: Microsoft Azure RSA TLS Issuing CA 08

Issuer: DigiCert Global Root G2

Expiration Date: 25-Aug-2026

We also verified that DigiCert Global Root G2 is already present in the trust store and remains valid until 2038.

According to the Microsoft Entra Certificate Authority documentation, this CA is listed as one of the subordinate CAs used by Microsoft services.

Could Microsoft please clarify the following:

  1. Which certificate will replace Microsoft Azure RSA TLS Issuing CA 08 after its expiration?
  2. Is the replacement certificate already published and available for download?
  3. Does Microsoft provide advance notification of such CA transitions?
  4. Will the replacement certificate continue to chain to DigiCert Global Root G2?
  5. Is any action required for customers maintaining custom trust stores, such as SAP STRUST, before 25-Aug-2026?

We are asking this question proactively to ensure there is no impact to SAP integrations relying on Microsoft services.

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.