Clients use Microsoft’s public GVLK for their edition. They auto-discover the KMS host via DNS.

Append your internal CA chain to the client trust store or update configuration to support older TLS versions if legacy clients are required.