Microsoft now issues the certificate itself
Microsoft has taken over the certificate work for Power Pages custom domains. The Power Platform Blog post, published September 16, 2026 and authored by Ritwik Ganni, says Microsoft now provisions, configures and renews SSL and TLS certificates itself, which takes away the purchase step, the PFX upload and the renewal tracking that came with them.
The option shows up in the Connect Custom Domain wizard in the Power Platform Admin Center, listed as Add Microsoft Managed certificate. Microsoft says configuration typically completes in a few minutes. The post puts no price on it, names no issuing authority and gives no validity period, so anyone whose security review asks those questions will be asking Microsoft directly.
An expired certificate on a public Power Pages site is one of the most avoidable outages in this line of work, and it keeps happening anyway. Renewal depends on somebody remembering a date, and that somebody is often the person who stood the site up two jobs ago.
The step that actually fails is the one being removed
Certificates rarely break because the cryptography went wrong. They break because a purchase order sat in an inbox for three weeks, or the PFX password lived in a document nobody could find, or the calendar reminder went to a mailbox that was closed when its owner moved teams.
Taking purchase, upload and renewal tracking out of the process removes all three of those failure modes at once. That is a genuine gain for a two-person platform team, and it sits in the same family as every other kind of ownership debt that only surfaces once the original owner has gone.
The site still needs a named human. Somebody has to hold the domain registration, the DNS records and the admin access that allows any of this to change. Managed certificates take one recurring chore off that person's list without removing the role or the need to write down who has it.
Existing sites keep running and stay where they are
Microsoft is explicit about what does not happen on its own. "Continued certificate choice preserves support for bring-your-own certificates. Existing sites are not migrated automatically and continue to operate without any impact."
So nothing shifts in your tenant this week unless you go and shift it. Your current certificate keeps serving traffic and keeps expiring on the same date it always would, which means the reminder you set last year is still the thing standing between you and a browser warning on a customer-facing portal.
Moving is a deliberate act. To put a live domain onto a Microsoft-managed certificate you remove the current SSL binding and the certificate, then reconnect the domain. On a public site with real traffic, that sequence wants a change window and somebody watching, not a spare afternoon between meetings.
The people who want this most may not see the button
Nick Doelman's ReadyXRM post, dated September 18, 2026, adds a detail the Microsoft announcement leaves out. The Microsoft-managed option does not appear at all if CDN or WAF is enabled on the site.
Consider who that rules out. A Power Pages site sitting behind a web application firewall is usually the one with real customers on it, real data behind the forms and a security team who asked for the firewall in writing. Those are the sites where an expired certificate costs the most, and where nobody has spare attention for renewal paperwork.
The smallest sites, the ones with a handful of internal users and no CDN in front of them, get the easy path. The portals that would gain most carry on buying certificates and tracking dates by hand. Microsoft's post says nothing about the restriction, so the first place many admins will meet it is a wizard step that never offers the choice.
What to check in the Admin Center today
Open the Connect Custom Domain wizard on one site and look for Add Microsoft Managed certificate. If the option is missing, check whether CDN or WAF is switched on before you raise a ticket, because the independent write-up gives that as the reason rather than anything broken in your tenant.
Then find out when each of your current certificates expires and who is named on the renewal. If that answer takes more than five minutes to produce, you have found the exact risk this announcement is aimed at, and it sits there whether or not you can use the new option. Put the dates and the owner into the runbook for the week you are away while you have the tab open.
For the sites that do qualify, book the switch into a change window rather than slipping it in quietly. Pulling a binding off a live public domain belongs in front of a change approval board that moves, with a rollback plan that assumes you still hold the old certificate and its password, because you will want both if the reconnect does not go cleanly the first time.



