Skip to main content

Certificate Management- Policies

Certificate Management installs or removes digital certificates across your endpoints- for example pushing a trusted root CA to every machine. A policy says which certificate to install (and into which stores) or which to delete.

Edition & permission

Device Control is EndpointOps edition. You need View Certificate Management permission.

How to get here

  1. In the left sidebar, click Device Control.
  2. Click the Certificate Management card.

Navigate to: Device Control → Certificate Management → Policies

URL path: /device-control/certificate-management-settings/policies

The Policies screen

The Certificate Management policies listThe Certificate Management policies list
ColumnWhat it shows
Policy NameThe policy name.
DescriptionWhat it's for.
Configuration LevelComputer or User store.
OperationInstall or Delete.
Certificate StoresThe target stores.

Create adds a policy; rows have Edit and Delete.

How do I create a policy?

Click Create. The form opens in a drawer.

The Create Certificate Management policy formThe Create Certificate Management policy form
FieldRequiredNotes
Policy NameYesThe policy name.
DescriptionNoWhat it's for.
Configuration LevelYesComputer or User- sets which stores are available.
OperationYesInstall or Delete.

For an Install operation:

FieldRequiredNotes
Certificate StoreYesOne or more target stores (Trusted Root, Personal, Trusted Publisher, etc.).
Certificate FileYesUpload the certificate (.cer, .pfx, .p7b).
PasswordNoFor an encrypted (.pfx) certificate.

For a Delete operation, choose Delete All Expired, or Delete Specific and give the certificate's Common Name and/or Serial Number.

Save to add the policy, then deploy it.