Guides / Chrome or Edge: Your connection is not private at work
Last reviewed 5 Oct 2026
Chrome or Edge: Your connection is not private at work
NET::ERR_CERT_AUTHORITY_INVALID on office Wi-Fi? How to tell SSL inspection from a real bad certificate without turning security off.
Chrome shows Your connection is not private. Edge says the same with a slightly different wallpaper. The code is often NET::ERR_CERT_AUTHORITY_INVALID, ERR_CERT_COMMON_NAME_INVALID, or ERR_CERT_DATE_INVALID. Users click Advanced and look for a bypass. On a work PC that bypass is the wrong move until you know whether this is your company's TLS inspection doing its job or a genuinely bad certificate on the internet.
Is the website down?
Run the host through our checker and open the site on a phone using mobile data. If LTE loads the site with a normal padlock and the office PC does not, the website is up and your path is rewriting TLS. If every network fails with a name mismatch or an expired certificate, the site's certificate is the incident — check whether they posted on their status page.
Office SSL inspection (the common case)
Many companies decrypt HTTPS on a firewall or secure web gateway so they can apply DLP and malware scanning. The firewall presents a certificate signed by an internal root CA. That only works when the work PC trusts that root. When the root is missing — new PC, non-domain device, Firefox with its own store, or a failed GPO — every HTTPS site looks hostile.
- Confirm the issuer. Click the error details / view certificate. If the issuer is your company name, "Firewall", "Proxy", "Gateway", or a vendor such as Zscaler, Netskope, Fortinet or Palo Alto, you are looking at inspection, not a broken bank website.
- Work laptop versus personal device. Personal phones on guest Wi-Fi often fail inspection because they lack the company root. That is expected. Use guest / BYOD rules your IT published — do not install random root certificates from email attachments.
- Ask IT for the root package. Domain-joined Windows PCs should get the root via policy. Entra-joined / Intune devices need a trusted certificate profile. Until that lands, only apps that ignore the system store will work, which is not a fix.
- Firefox note. Firefox can use its own certificate store. Either enable "security.enterprise_roots.enabled" per your IT standard or import the corporate root the way they document.
When the certificate really is bad
- Name mismatch (
ERR_CERT_COMMON_NAME_INVALID): the certificate does not cover the hostname you typed (www versus apex, old CDN name, wrong internal server). - Expired / not yet valid (
ERR_CERT_DATE_INVALID): check the PC clock first. A wrong date produces a spectacular number of false alarms. If the clock is right, the site's certificate expired. - Revoked or incomplete chain: less common on public sites, more common on internal IIS servers missing intermediate certificates.
What not to do
Do not tell the whole company to click Proceed. Do not disable TLS inspection yourself to "make Chrome work". Do not install a root CA that arrived as a side-loaded file from an unofficial chat. Those are how credential-stealing proxies win.
Admin checklist
- Confirm the inspection CA is deployed to Intune / GPO / Jamf and that new Autopilot devices receive it before users browse.
- Exclude apps that break under inspection (some banking apps, certificate-pinned clients, software updates) via your gateway's recommended bypass list — not by teaching users to ignore warnings.
- Monitor the gateway's own status; a failed inspection appliance can present broken certificates even when the destination site is healthy.
When to escalate
Escalate to the network or security team when new images lack the root, when inspection breaks a pinned vendor app that has no supported bypass, or when an external site shows a bad certificate from every network. Escalate to the website owner when the certificate is expired or mismatched on the public internet. Include the hostname, error code, certificate issuer screenshot, and whether LTE works.
Related status pages
Related guides
- Why a site works for everyone else but not me
- VPN connected but no internet or can't reach internal sites
- How to tell if a service is down or it's just you
FAQ
- What does NET::ERR_CERT_AUTHORITY_INVALID mean at the office?
- Usually the corporate firewall is inspecting HTTPS and your PC does not trust the company root certificate. View the certificate issuer — if it is your company or security vendor, ask IT to deploy the root, do not bypass casually.
- Why does my phone work on mobile data but not office Wi-Fi?
- Office Wi-Fi often uses SSL inspection that only managed devices trust. Mobile data talks to the site directly. That split is a strong sign the website is up.
- Should I click Advanced and proceed?
- Not as a habit on a work PC. Proceeding through an inspection warning you do not understand can hide a real attacker proxy. Get the right root certificate or use a path IT supports.
- Can a wrong PC clock cause certificate errors?
- Yes. Certificates have validity dates. Set time automatically and retest before rebuilding browsers or firewalls.