<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Troubleshooting Error "Digital signature in the SAML response did not validate with the Identity Provider's certificate"

Single Sign-On
Okta Classic Engine
Okta Identity Engine

Overview

With Entra ID as the Identity Provider (IdP) and Okta as the Service Provider (SP), the following errors may be seen when attempting to sign into Okta:
 

Authenticate user via IDP FAILURE: Unable to validate incoming SAML Assertion
 

Error Message

 

The digital signature in the SAML response did not validate with the Identity Provider's certificate

 

Error Message

 

 

Applies To

  • Entra ID
  • Single Sign-On (SSO)
  • Certificate error

Cause

The certificate uploaded to Okta from Entra ID is either expired or incorrect and does not match the current, valid certificate downloaded from Entra ID.

Solution

  1. Download the certificate from Entra ID by navigating to Microsoft Entra admin center > Applications > Enterprise applications > [Enterprise App Name] > Single sign-on > SAML Certificates > Certificate (Base64).

Download certificate

  1. Delete the certificate in the Okta Admin Console by navigating to Security > Identity Providers > select the [Name of IdP] > click Actions dropdown menu > select Configure Identity Provider > click Edit >  click X in the IdP Signature Certificate section.IdP Signature Certificate section   

  2. Upload the new certificate downloaded from Entra ID.

Upload the new certificate 

Loading
Okta Support - Troubleshooting Error "Digital signature in the SAML response did not validate with the Identity Provider's certificate"