
New in Microsoft Marketplace: June 26, 2026
June 26, 2026Practice the Hard Call: Real-Time Voice Training with Live Voice Practice
June 26, 2026The technology industry is retiring trust in an older root certificate – the DigiCert Global Root G1. As operating systems, firmware images, and CA certificate bundles update over time, some clients may stop trusting this older root. This can affect both your Azure IoT devices and the applications that connect to Azure IoT service APIs. If those devices or application hosts run on Linux or rely on a system trust store that receives periodic updates, this post explains what you might see and the simple steps to stay connected. This guidance is relevant only for a subset of Azure IoT customers using Azure Government (Fairfax) or Azure China (Mooncake) environments, and only if devices or applications adopt operating system, firmware, or trust-store updates that remove trust for the DigiCert Global Root G1 certificate. Azure public cloud customers are not affected because Azure IoT public cloud endpoints already use newer certificate chains. This is a client-side trust-store change, not a security incident, service outage, or certificate expiration event. Scope: Azure public cloud customers are not affected. This guidance applies only to specific Azure Government (Fairfax) and Azure China (Mooncake) scenarios where updated client trust stores no longer trust DigiCert Global Root G1. For most Azure IoT customers, the answer is no. If you use Azure IoT in the Azure public (commercial) cloud, you are not affected by this change. Azure IoT public cloud endpoints already use newer certificate chains and do not rely on the DigiCert Global Root G1 certificate. This guidance is relevant only for a subset of customers using Azure Government (Fairfax) or Azure China (Mooncake) environments, and only if: If your devices continue to connect normally and you have not observed any TLS-related issues following recent updates, no action is required at this time If your devices and applications are connecting normally, no action is required. If you manage Linux-based devices or applications that rely on operating system trust stores, we recommend validating OS, firmware, and CA bundle updates in a test environment before production rollout. If connectivity issues appear following a trust-store update, contact Microsoft Support for assistance. After an operating system, firmware, or CA-certificate-bundle update, an affected device or application may show the symptoms below. These typically appear first in test or QA environments, because fleets and application environments usually stage updates before production. Your device or application validates the Azure IoT server certificate against the list of trusted root certificates in its local trust store. As updates remove the older DigiCert Global Root G1 from that store, a client that still expects it may reject the connection – even though the server certificate is valid. The change is on the client side, in the trust store, not in the Azure service. If you see connectivity or provisioning failures, confirm the following: A few simple steps keep your devices and applications connected through this change: If you have questions, contact Microsoft Support or your Microsoft account team.
At a glance
Could this affect my deployment?
What should I do?
What you may observe
Why it could happen
What you should check
What we recommend
Questions