@rlewi17 When it comes to a certificate's issuance policy:
If a certificate's policy is set to auto renewal, then a notification is sent on the following events.
- Before certificate renewal
- After certificate renewal, stating if the certificate was successfully renewed, or if there was an error, requiring manual renewal of the certificate.
When a certificate policy that is set to be manually renewed (email only), a notification is sent when it's time to renew the certificate.
You can also integrate Azure Key Vault with Azure Policy if you'd like to manage your certificates even further with new built-in policies (preview).
Additional links:
Configure certificate auto-rotation in KV
Please let us know if any reply/answer helped resolve your question. If so, please remember to "mark as answer" so that others in the community facing similar issues can easily find a solution.