Use Group Policy to push exchange self-signed certificates
I. Export certificate
Open the certificate authority, select the properties above the certificate server, and then follow the figure below to export.
When selecting the format, follow the logo in the above picture.
Second, import certificates
Create a new group policy, select trusted Root Certificate Authority in computer configuration-policies-windows Settings-Security Settings-Public key Policy and create a new import.
III. Testing
After the client updates the group policy, it is found that the login mailbox address is no longer prompted to be untrusted.