
GiulioM.24800 (Customer) asked a question.
Update SSO WS-Fed Cert for M365 Clarification
So my M365 SSO Okta Cert expires tomorrow. Is the process as simple as creating the new cert in the Entra M365 OKTA app and then do a Fetch and Select in the Okta Admin M365 Sign On WS Fed Section? I am not seeing anything with clarity on the renewal of this cert.

Updating this response for ease of access and reference:
When a Microsoft 365 Single Sign-On (SSO) certificate approaches expiration, the administrator must generate the token-signing certificate in Okta first because Okta acts as the Identity Provider (IdP). Afterward, the administrator must update Microsoft Entra to trust the new certificate. The exact rotation process depends on whether the WS-Federation configuration in Okta uses automatic or manual settings.
Applies To
Solution
How does Okta renew the Microsoft 365 Single Sign-On certificate using automatic updates?
If the WS-Federation configuration allows Okta to automatically manage the settings, Okta handles the Microsoft backend update automatically. Generate and activate the new certificate in the Okta Admin Console by completing the following actions.
Okta immediately pushes the new certificate to Microsoft 365. Wait approximately five minutes for the changes to propagate, then test a login in a fresh incognito window.
Manual updates require PowerShell to renew the Microsoft 365 Single Sign-On certificate.
If the Microsoft Office 365 application uses manual settings, the administrator must use PowerShell to update Microsoft Entra ID with the new certificate string before activating it in Okta.
NOTE: Do not activate the new certificate in Okta until the PowerShell command successfully updates Microsoft Entra ID. Activating the certificate too early immediately breaks all Microsoft 365 Single Sign-On logins.
Generate the certificate, extract the metadata, and update Microsoft Entra ID via PowerShell by completing the following actions.
To verify the success of either method, open an incognito browser and attempt to log in to portal.office.com. If the session seamlessly redirects to Okta and back to Microsoft 365, the rotation is complete.