Share via


ReadExtendedCertificateLocationsEnabled

Enable Extended Keychain Certificate Authentication

Supported versions

  • On iOS since 142 or later

Description

This policy controls whether Microsoft Edge can use certificates from extended keychain locations for client certificate authentication.

If you enable this policy, Microsoft Edge is allowed to read certificates from the com.apple.token keychain group (requires user permission) and Intune-derived credentials keychain groups when requested by servers for client certificate authentication.

If you disable or don’t configure this policy, Microsoft Edge doesn't access these extended keychain locations for client certificate authentication.

Supported features

  • Can be mandatory: Yes
  • Can be recommended: No
  • Dynamic Policy Refresh: Yes
  • Per Profile: Yes
  • Applies to a profile that is signed in with a Microsoft account: No

Data type

  • Boolean

iOS information and settings

  • Preference Key name: ReadExtendedCertificateLocationsEnabled
  • Example value:
<true/>

See also