Client certificate in LocalMachine\My not appearing in Edge certificate selection dialog

Ariel, Yu Lan 20 Reputation points
2026-09-24T05:19:00.1233333+00:00

Hello,

I am investigating how Microsoft Edge discovers client certificates for mTLS authentication.

I have observed the following behavior:

  • A client certificate installed in CurrentUser\My appears correctly in the Edge certificate selection dialog.
  • The same certificate contains a private key and can be used successfully for client authentication.
  • However, after moving the exact same certificate from CurrentUser\My to LocalMachine\My, it no longer appears in the Edge certificate selection dialog.
  • A custom .NET application can still access and use the certificate from LocalMachine\My successfully.

My questions are:

  1. Does Microsoft Edge support selecting client certificates from LocalMachine\My?
  2. If yes, what requirements must be met for a certificate in LocalMachine\My to be eligible for selection?
  3. Does Edge intentionally limit client certificate selection to CurrentUser\My, or are machine-store certificates also supported under certain conditions?

Any clarification or official documentation would be greatly appreciated.

Thank you.

Microsoft Edge | Website issues | Windows 11
0 comments No comments

Answer accepted by question author
Carl-L 23,090 Reputation points Microsoft External Staff Moderator
2026-09-25T06:37:59.61+00:00

Hello Ariel, Yu Lan,

Welcome to Microsoft Q&A forum.

For a quick answer, for client certificates, you should left them at CurrentUser\My.

As I checked, Edge currently doesn't state LocalMachine\My for TLS certificate picker, so I wouldn't say that it is supported. And yes, there is absolutely extra certificate selection requirements beyond the normal TLS picker. However, I wouldn't be sure if satisfying those requirements can make LocalMachine\My available for selection.

About the CurrentUser\My, yes, it is special. The LocalMachine inherits all information and certificate to all stores, except for CurrentUser\My. So when you move certificate, the one in localMachine might not be accessible by CurrentUser, which Edge taking from.

I hope this clarifies.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Oldest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.