Thanks! Yes, but sometime we have seen that customers don’t have Trusted CA in place specially for Lower Environments (In case they have a custom domain which don’t have CA). For PROD, we have a Trusted CA. In those cases, the only way to do it is using Self Signed Certificate which is also recommended to us by SailPoint. Also, with the latest release of IQ Service on July-2025, they have made TLS enablement mandatory for triggering the AD Connector Rule Scripts. Hence, in case, you lower environments on which your IQ Service is hosted do not have Trusted CA in place, then, Self Signed Certificate usage is the only option or else a trusted CA has to be there.