A certificate authority on your device is software that your computer or phone uses to verify that websites and apps are who they claim to be

When you see a message saying "a certificate authority is installed on this device," your operating system is telling you that a trusted verification program has been added to your system. This program acts as a gatekeeper—it checks digital certificates (the credentials websites and apps present) and decides whether to trust them. Most of the time, your device comes with certificate authorities already built in. When you see this message, it usually means a new one has been added, either by you, your workplace, your school, or security software you installed.

The certificate authority itself does not spy on you or steal data. Its job is narrow: to verify that the certificate a website or app shows you is real and hasn't been forged. Think of it like a notary public for the internet. However, because a certificate authority sits in a position of trust on your device, it's worth understanding why it's there and whether you put it there intentionally.

Key Takeaways

  • A certificate authority installed on your device is a verification tool that checks whether websites and apps are legitimate before your device trusts them.
  • Workplace networks, schools, and security software often install their own certificate authorities so they can monitor traffic on their network or devices.
  • If you did not install it yourself and do not recognize who added it, you should find out what program or organization put it there before removing it.
  • Removing a certificate authority your workplace or school installed may break your ability to access their network or services.
  • On Windows, you can view installed certificate authorities in the Certificate Manager; on Mac, check the Keychain; on iPhone or Android, look in Settings under Security or Certificates.

Why certificate authorities get installed on your device

Your device ships with a set of trusted certificate authorities—companies like DigiCert, Sectigo, and Let's Encrypt that have been vetted by your operating system maker. These are the "roots" that verify most of the websites you visit every day.

New certificate authorities are added when an organization wants to inspect the traffic on its own network. A workplace might install one so it can scan email and web traffic for malware or policy violations. A school might install one to filter content on school networks. Antivirus software, parental control software, and VPN apps sometimes install their own certificate authorities too, so they can see encrypted traffic and check it for threats.

The key difference: a certificate authority installed by your workplace or school can see your encrypted traffic while you are on their network or using their device. A certificate authority installed by antivirus software can potentially see your traffic on any network, depending on how the software is configured. This is why it matters to know which ones are on your device and who put them there.

How to find out which certificate authorities are installed

On Windows: Open the Start menu, type "certmgr.msc" and press Enter. This opens the Certificate Manager. Look for the "Trusted Root Certification Authorities" folder. Expand it and scroll through the list. You will see the names of certificate authorities—look for any that seem unfamiliar or that you do not remember installing. Right-click one to see its properties and find out who issued it.

On Mac: Open Spotlight (Command + Space), type "Keychain Access" and press Enter. In the window that opens, select "System Roots" in the left sidebar. You will see a list of certificate authorities. Look for any that stand out as unusual. Double-click one to see more details about who issued it.

On iPhone: Go to Settings, then General, then About, then Certificate Trust Settings. You will see a list of installed certificate authorities. Any that are not from Apple or major companies like DigiCert are worth investigating.

On Android: Go to Settings, then Security (or Privacy, depending on your phone), then Encryption and Credentials, then Trusted Credentials. You will see a list of installed certificate authorities. Tap one to see details.

When a certificate authority from your workplace or school appears

If you see a certificate authority with your company name, school name, or your IT department's name on it, that is almost certainly intentional. Your workplace or school installed it so they can monitor traffic on their network and devices. This is legal and common, especially on devices the organization owns or on networks they control.

If you are using a personal device on a work network and you see a work certificate authority, it means your organization is inspecting your traffic while you are connected to their network. Once you disconnect, the certificate authority is still on your device, but it only works on their network.

Do not remove a certificate authority your workplace or school installed unless you have been told to do so by your IT department. Removing it may break your ability to access email, internal websites, or network resources. If you are unsure whether a certificate authority belongs there, contact your IT support team and ask them to confirm.

When a certificate authority from security software appears

Antivirus programs, VPN apps, and parental control software sometimes install their own certificate authorities. If you installed one of these programs and then saw a message about a new certificate authority, the two are almost certainly connected.

Check the documentation or settings of the security software to confirm. Most reputable programs will tell you during installation that they are adding a certificate authority. If you did not see that notification and do not recognize the certificate authority's name, search the internet for the name along with the word "certificate" to find out what program installed it.

Be cautious about security software from unknown vendors. A certificate authority is a powerful tool—it can see all your encrypted traffic. Only install security software from companies you trust, and only from official sources like the Microsoft Store, Apple App Store, or Google Play Store.

When you do not recognize the certificate authority

If you see a certificate authority you did not install and cannot connect to a known program or organization, do some detective work before removing it. Search the internet for the exact name of the certificate authority. Look for the organization that issued it—this information is usually in the certificate's properties.

If you still cannot figure out where it came from, ask yourself: Did someone else use this device? Did you recently install new software? Did you connect to a public Wi-Fi network that required you to install something? Did your device get repaired or serviced by someone else?

If you are confident the certificate authority should not be there and you cannot find out who installed it, you can remove it. On Windows, right-click the certificate in Certificate Manager and select Delete. On Mac, right-click it in Keychain Access and select Delete. On iPhone or Android, go to Settings, find the certificate, and look for a Delete or Remove option. However, be aware that removing a certificate authority your device needs may cause problems—if something stops working after you remove it, you may need to reinstall it or contact support.

What happens if you remove a certificate authority you need

If you remove a certificate authority that your workplace, school, or security software needs, you will likely see error messages when you try to access certain websites or services. The error will usually say something like "certificate not trusted" or "security certificate problem."

The fix is straightforward: reinstall the certificate authority. If it was from your workplace or school, contact your IT department and ask them to reinstall it. If it was from security software, reinstall the software. If it was a root certificate authority that came with your operating system, you may need to run a system repair or update to restore it.

Frequently Asked Questions

Does a certificate authority on my device mean someone is spying on me?

A certificate authority itself is not spying software. However, if it was installed by your workplace or school, it means they can see your encrypted traffic while you are on their network or using their device. If it was installed by antivirus software, that software can inspect your traffic depending on how it is set up. The certificate authority is a tool—what matters is who installed it and what they are doing with the information they see.

Can I remove a certificate authority without breaking my device?

You can remove most certificate authorities without breaking your device. However, if you remove one your device depends on—such as one from your workplace, school, or security software—you may lose access to certain services or see security warnings. If something stops working, you can reinstall the certificate authority or contact the organization that installed it for help.

Why did a certificate authority appear after I installed antivirus software?

Antivirus software often installs a certificate authority so it can inspect encrypted traffic for malware and threats. This is normal. Check the software's settings or documentation to confirm. If you did not authorize this during installation, review the software's privacy policy or contact the vendor to understand what traffic they are inspecting.

Is it safe to have multiple certificate authorities on my device?

Yes. Your device comes with dozens of trusted certificate authorities built in, and adding more from your workplace, school, or security software is normal and safe. The more certificate authorities you have, the more organizations can verify their identity to you—but each one only works within its intended scope (a workplace network, a specific app, and so on).

What should I do if I see a certificate authority I definitely did not install?

First, search the internet for its name to find out what program or organization installed it. Check your installed software list to see if a recent installation matches. If you still cannot figure it out and you are confident it should not be there, you can remove it. If removing it causes problems, reinstall it or contact your IT support team. If you suspect malware, run a full antivirus scan.