G DATA MXDR

What is the Microsoft code-signing certificate required for?

The Agent executables are digitally signed. For Windows to verify this signature before execution, the following root certificate must be installed in the Windows Trusted Root Certification Authorities store. Normally, this certificate is installed by default via Windows Update.

In isolated environments, or in environments in which Windows updates are distributed via WSUS or other patch management systems, it has often happened in the past that root certificate updates are not performed regularly.

Which certificate is required?

The Microsoft Identity Verification Root Certificate Authority 2020 certificate is required, with the SHA-1 fingerprint shown below.

F40042E2E5F7E8EF8189FED15519AECE42C3BFA2

You can download the certificate from https://www.microsoft.com/pkiops/docs/repository.htm. To do so, search for "Microsoft Identity Verification Root Certificate Authority 2020" on the specified page and download the corresponding certificate. Add it to the Windows Trusted Root Certification Authorities store.

If you would like to test whether the certificate is present, you can verify this with the following PowerShell command.

Get-ChildItem -Path Cert:\LocalMachine\Root | Where-Object { $_.Thumbprint -eq "F40042E2E5F7E8EF8189FED15519AECE42C3BFA2" }