Notifications
certmon reports findings over channels (e-mail over SMTP or Microsoft 365, Microsoft Teams, webhook); rules decide which findings go where (Settings > Notifications, administrators). Tag and owner filters use the effective values: the source's tags plus those of the device or server, and its owner, otherwise the source's (set on the device or server page; thresholds there and per tag under Settings > Monitoring, effective from the next run).
- Alert logic: state changes (new, worse, better, resolved) once per rule and change; reminders before expiry (30/14/7/3/1 days) and daily while critical; escalation after X hours for findings nobody acknowledged; daily or weekly digest; maintenance windows and quiet hours postpone; signed one-time links (7 days) open the dashboard, the action requires a signed-in operator. Up to 5 delivery attempts, then event 1600.
- SMTP: STARTTLS (587 or 25) with a trusted server certificate; no implicit TLS (465). Plaintext only through the explicit switch "send without STARTTLS" for internal relays, and only without sign-in (credentials are rejected and never sent); the channel is flagged "unencrypted" and the choice is audited.
- Microsoft Graph: app registration, certificate in
LocalMachine\My(preferred) or client secret; grantApplication Mail.Sendscoped to the sending mailbox with RBAC for Applications in Exchange Online (commands above) and do not consentMail.Sendin Entra ID (it would apply to all mailboxes). - Teams: Workflows template "Post to a channel when a webhook request is received"; the URL is a secret.
- Webhook: JSON schema 1 (example above), HMAC-SHA256 over
"{timestamp}.{body}"inX-Certmon-Signature(sha256=<hex>), timestamp inX-Certmon-Timestamp, delivery id inX-Certmon-Delivery. Verify on the raw body, compare in constant time, reject timestamps older than 5 minutes. - All channel secrets are encrypted (DPAPI) and never shown, logged or exported; outgoing TLS 1.2/1.3 only, certificate validation, no redirects.
More documents
Installation and setup
Requirements, firewall, service account, permissions, setup (also silent), initial setup, update, backup and troubleshooting.
JEA endpoint for Windows servers
How certmon reads Windows servers only through a restricted PowerShell endpoint: setup, permissions, testing.
Findings
Every finding id with its meaning and severity: network scan, PKI and Windows servers.
Windows event log
Event ids of the certmon source for RMM and SIEM systems, with query examples.