Press ESC to close

Maxime RastelloMaxime Rastello Microsoft 365, Azure, Identity, Security & Compliance, Enterprise Mobility, Workplace

Avoid certificate prompt for Azure Active Directory Certificate-Based Authentication (CBA)

Azure Active Directory Certificate-Based Authentication (Azure AD CBA) allows you to authenticate to Azure Active Directory using a certificate from your internal Public Key Infrastructure (PKI). To know how to implement Azure Active Directory CBA, please refer to the Microsoft doc.


Certificate authentication will happen on the URL By default, your web browser will prompt you to select a certificate installed on your Personal User Certificate store.


To avoid the user to manually select a user certificate for authentication, you can use the following parameters with Microsoft Edge :




Create the following registry key either in CURRENT_USER or LOCAL_MACHINE :

  • Type : REG_SZ
  • Name : 1 (or any following number if you already have parameters configured here)
  • Location :
    • User setting: HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Edge\AutoSelectCertificateForUrls
    • Device setting: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\AutoSelectCertificateForUrls
  • Value : check below





Create a GPO in Active Directory or a Settings Catalog profile in Microsoft Endpoint Manager and set the following parameter :

  • Parameter : Automatically select client certificates for these sites
  • Location : Administrative Templates / Microsoft Edge / Content settings
  • Value : check below



Parameter value

Here is a generic sample of the possible values for the parameter:

{"pattern":"","filter":{"ISSUER":{"CN":"certificate issuer name", "L": "certificate issuer location", "O": "certificate issuer org", "OU": "certificate issuer org unit"}, "SUBJECT":{"CN":"certificate subject name", "L": "certificate subject location", "O": "certificate subject org", "OU": "certificate subject org unit"}}}


Make sure you customize the JSON parameters based on your needs and apply it to the pattern

Here is my example:


Replace AZURE-CA by the CN of your issuing CA



You can check that the setting is properly applied in Microsoft Edge using the tag edge://policy



To validate the automatication certificate selection:

  1. Restart Microsoft Edge
  2. Go to
  3. You should be automatically authenticated and redirected to

Comments (1)

  • briansays:

    15/04/2023 at 00:40

    Is there a similar reg key for microsoft office 365, using CBA i get prompted once when launching any office product?

Leave a Reply

Your email address will not be published. Required fields are marked *