Thank you for taking the time to share thoughtful and detailed feedback. We really appreciate the perspective you’re bringing here, especially given your experience helping customers deploy Microsoft Connected Cache at scale.
The HTTPS enforcement timeline is driven by Microsoft’s security requirements and can’t be delayed further, but we’re focused on reducing the operational burden for customers to meet it. While Connected Cache already performs hash validation on HTTP requests, HTTPS is required for certain content types (Teams updates require https).
You’re absolutely right that TLS certificates are not a one-time task. We understand that expiration, renewal, and operational scale are challenging to IT Administrators. The feedback we’re seeing reinforces that certificate lifecycle management needs to be practical, not just secure.
The CSR-based workflow was designed as an initial step that allowed us to meet security and compliance requirements and deliver validated HTTPS support with GA, with the expectation that additional capabilities would build on this foundation.
“Bring Your Own Certificate” is one of those capabilities. This feature has been, and will continue to be, a top priority for Connected Cache. The goal is to let customers continue using their existing PKI investments, renewal processes, and automation, without per-node scripting or manual overhead.
We don’t have a specific timeline to share yet, but this feedback is further pushing our near-term priorities. We’ll continue to provide updates through our documentation and Tech Community posts as capabilities evolve.