Windows has separate certificate stores for the current user and the local computer. Open the manager that matches the certificate you need to inspect.
- Press Windows+R.
- Enter
certmgr.mscand press Enter to open certificates for the current user. - Expand folders such as Personal or Trusted Root Certification Authorities to inspect their contents.
- For the local-computer store, use the Certificates snap-in in Microsoft Management Console with appropriate administrative authorization.
- Close the console without changing certificates unless you know exactly what the certificate is used for.
Be careful with trusted roots
Adding a root certificate can cause Windows and applications to trust identities signed by that authority. Do not import unknown root certificates merely to silence a browser or application warning.
Deleting certificates can break services
Removing a certificate can affect Wi-Fi, VPN, encrypted files, smart cards, websites, application signing, or organization authentication. Export a needed certificate appropriately and consult the administrator before changes.
Expired does not always mean delete
Old certificates can remain relevant for verifying historical signatures or archived encrypted material. Determine purpose and chain before cleanup.
Windows 10 lifecycle
The certificate tools remain useful, but Windows 10 itself ended standard support in 2025.
Certificate details
Double-clicking a certificate can show its subject, issuer, validity dates, intended purposes, thumbprint, and certification path. Use those details to identify it rather than relying only on a friendly display name.

Kermit Matthews is a freelance writer based in Philadelphia, Pennsylvania with more than a decade of experience writing technology guides. He has a Bachelor’s and Master’s degree in Computer Science and has spent much of his professional career in IT management.
He specializes in writing content about iPhones, Android devices, Microsoft Office, and many other popular applications and devices.