The ISA Portal is signed with the modern root certificate "USERTrust RSA Certification Authority". It is also cross-signed with the root certificate "AAA Certificate" to increase support for older/legacy devices with outdated Trusted Root CA Certificate Stores. A modern browser would have the "USERTrust RSA Certification Authority" root already installed and trust it without needing to rely on the cross-signed "AAA Certificate". A legacy browser or older device that does not have the modern “USERTrust RSA Certification Authority” root would not trust it and would look further up the chain to a root it does trust, i.e. the "AAA Certificate". If both “USERTrust RSA Certification Authority” and "AAA Certificate Services" root certificates are missing, the certificate of the ISA Portal would not be trusted, and not load as expected. This in turn may lead to errors while installing and configuring or even connecting the ISA App.
The Trusted Root CA Certificate Store is typically updated by the browser software or the device OS frequently, often as part of security updates, and on older outdated platforms it might be updated only as part of a full software update – such as Windows Service Packs or optional Windows Update releases. It's also possible that certain GPO settings might pose a problem, for example: if the GPO setting Computer Configuration\Administrative Templates\System\Internet Communication Management\Turn off Automatic Root Certificates Update is Enabled, the OS wouldn't pull root CAs from Microsoft.