Scheduled Certificate Authority (CA) Update – api.adnxs.com

Scheduled for Apr 13, 16:30 - 17:30 UTC

Scheduled

Dear Microsoft Customer,

We will be updating the TLS certificate used by the api.adnxs.com endpoint on April 13, 2026 at 16:30 UTC (12:30pm EDT)

As part of this change, the root Certificate Authority (CA) in the certificate chain will be updated.
- Current Root CA: DigiCert Global Root CA
- New Root CA: DigiCert Global Root G3

Clients who implement Root CA Pinning (i.e., explicitly trust only a specific root certificate for TLS connections) must ensure that the following certificate is added to their trusted certificate store prior to April 13, 2026 to avoid potential service disruption:
- New Root CA: DigiCert Global Root G3

You may download the new root certificate using one of the following methods:
- DigiCert Trusted Root Certificates: https://knowledge.digicert.com/general-information/digicert-trusted-root-authority-certificates
- Direct Download:
https://cacerts.digicert.com/DigiCertGlobalRootG3.crt.pem

After April 13, 2026, clients may remove the DigiCert Global Root CA from their trusted certificate store if it is no longer required by their environment or security policies. Clients not using Root CA Pinning are not expected to experience any impact and do not need to take any action.

If you have any questions, please contact us by creating a Customer Support ticket under support.ads.microsoft.com.

Best Regards,
Microsoft Support Team
Posted Apr 08, 2026 - 16:48 UTC