Windows Agent with own PKI Certificates

Hello in my Icinga environment I only use certificates from my own certificate infrastructure / PKI for everything. I do not use self-signed certificates from the master server.

How do I get the Windows Agent to use these certificates. I have already issued a certificate for the client on which the agent runs and under C:\Program Data\icinga2\var\lib\icinga2\certs\ I have stored the certificate and the CA certificate.

During setup, the CA is also recognized cleanly, but the existing client certificate is overwritten during the installation process.

What can I do?
Do I have the wrong approach?