Windows 10 can install trusted certificates for the current user or the local computer, but a certificate should be installed only when you know who issued it, why it is required, and which certificate store it belongs in. Installing an untrusted root certificate can allow that issuer to be trusted for security-sensitive connections. October 14, 2025 was the end of standard Windows 10 support.
Steps
Step 1: Verify the certificate first
Confirm the certificate came from your organization, device vendor, certificate authority, or another trusted source. Check its purpose and fingerprint through a trusted channel when your administrator provides one.
Step 2: Open the certificate file
For a CER or CRT file, double-click it and inspect the issuer, subject, validity dates, and other details before choosing Install Certificate.
Step 3: Choose the correct scope
Select Current User when the certificate is intended only for your account. Use Local Machine only when the certificate must apply system-wide and you have administrative authorization.
Step 4: Choose the certificate store
Use automatic store selection when the issuer or administrator’s instructions call for it. If you must select a store manually, choose only the store specified by the trusted documentation; do not place an arbitrary certificate in Trusted Root Certification Authorities.
Step 5: Complete and verify the import
Finish the Certificate Import Wizard, then test the application or service that required the certificate. If Windows presents a root-certificate security warning, verify the certificate again before accepting it.
What Happens Next
The certificate becomes available to Windows components and applications that use the selected certificate store. A successful import does not by itself prove that the certificate is trustworthy or appropriate.
Troubleshooting and Useful Details
Never install a root certificate sent unexpectedly by email, chat, a pop-up, or an unknown website. For work or school certificates, use the organization’s documented enrollment method. Windows 10’s standard support has ended, so certificate-sensitive workloads should be moved to a supported platform when feasible.

Matt Jacobs has been working as an IT consultant for small businesses since receiving his Master’s degree in 2003. While he still does some consulting work, his primary focus now is on creating technology support content for SupportYourTech.com.
His work can be found on many websites and focuses on topics such as Microsoft Office, Apple devices, Android devices, Photoshop, and more.