<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR000017sSbp0AEOkta Classic EngineSingle Sign-OnAnswered2026-09-22T20:13:37.000Z2026-01-02T17:37:03.000Z2026-09-22T20:13:37.000Z

GiulioM.24800 (Customer) asked a question.

Update SSO WS-Fed Cert for M365 Clarification

So my M365 SSO Okta Cert expires tomorrow. Is the process as simple as creating the new cert in the Entra M365 OKTA app and then do a Fetch and Select in the Okta Admin M365 Sign On WS Fed Section? I am not seeing anything with clarity on the renewal of this cert.


  • Paul S. (Okta, Inc.)

    Updating this response for ease of access and reference:

     

    When a Microsoft 365 Single Sign-On (SSO) certificate approaches expiration, the administrator must generate the token-signing certificate in Okta first because Okta acts as the Identity Provider (IdP). Afterward, the administrator must update Microsoft Entra to trust the new certificate. The exact rotation process depends on whether the WS-Federation configuration in Okta uses automatic or manual settings.

     

    Applies To

    • Okta Identity Engine (OIE)
    • Okta Classic Engine
    • Microsoft 365
    • Single Sign-On (SSO)
    • WS-Federation

     

    Solution

    How does Okta renew the Microsoft 365 Single Sign-On certificate using automatic updates?

    If the WS-Federation configuration allows Okta to automatically manage the settings, Okta handles the Microsoft backend update automatically. Generate and activate the new certificate in the Okta Admin Console by completing the following actions.

    1. In the Okta Admin Console, navigate to Applications and select the Microsoft Office 365 application.
    2. Select the Sign On tab.
    3. Scroll down to the SAML Signing Certificates section.
    4. Select Generate new certificate.
    5. Select the Actions menu for the newly generated certificate and choose Activate.

     

    Okta immediately pushes the new certificate to Microsoft 365. Wait approximately five minutes for the changes to propagate, then test a login in a fresh incognito window.

    Manual updates require PowerShell to renew the Microsoft 365 Single Sign-On certificate.

    If the Microsoft Office 365 application uses manual settings, the administrator must use PowerShell to update Microsoft Entra ID with the new certificate string before activating it in Okta.

    NOTE: Do not activate the new certificate in Okta until the PowerShell command successfully updates Microsoft Entra ID. Activating the certificate too early immediately breaks all Microsoft 365 Single Sign-On logins.

     

    Generate the certificate, extract the metadata, and update Microsoft Entra ID via PowerShell by completing the following actions.

    1. On the Sign On tab of the Microsoft Office 365 application in the Okta Admin Console, scroll to SAML Signing Certificates and select Generate new certificate. Leave the certificate as inactive.
    2. Select View IdP metadata from the Actions menu of the new certificate.
    3. Copy the long text block located inside the <X509Certificate>
    4. tags. Ensure there are no spaces or line breaks in the copied string.
    5. From the left sidebar in the Okta Admin Console, select View Setup Instructions and locate the PowerShell command under the Update the signing certificate section.
    6. Open PowerShell on the local machine and connect to Microsoft Graph as a Microsoft 365 Global Administrator by running the following command: Connect-MgGraph -Scopes Directory.AccessAsUser.All
    7. Paste and run the command from the Okta setup instructions, replacing the placeholder certificate value with the string copied in step three.
    8. Once PowerShell confirms the domain federation update, return to the Okta Admin Console and select Activate on the new certificate.

    To verify the success of either method, open an incognito browser and attempt to log in to portal.office.com. If the session seamlessly redirects to Okta and back to Microsoft 365, the rotation is complete.

    Expand Post
    Selected as Best
  • Paul S. (Okta, Inc.)

    Updating this response for ease of access and reference:

     

    When a Microsoft 365 Single Sign-On (SSO) certificate approaches expiration, the administrator must generate the token-signing certificate in Okta first because Okta acts as the Identity Provider (IdP). Afterward, the administrator must update Microsoft Entra to trust the new certificate. The exact rotation process depends on whether the WS-Federation configuration in Okta uses automatic or manual settings.

     

    Applies To

    • Okta Identity Engine (OIE)
    • Okta Classic Engine
    • Microsoft 365
    • Single Sign-On (SSO)
    • WS-Federation

     

    Solution

    How does Okta renew the Microsoft 365 Single Sign-On certificate using automatic updates?

    If the WS-Federation configuration allows Okta to automatically manage the settings, Okta handles the Microsoft backend update automatically. Generate and activate the new certificate in the Okta Admin Console by completing the following actions.

    1. In the Okta Admin Console, navigate to Applications and select the Microsoft Office 365 application.
    2. Select the Sign On tab.
    3. Scroll down to the SAML Signing Certificates section.
    4. Select Generate new certificate.
    5. Select the Actions menu for the newly generated certificate and choose Activate.

     

    Okta immediately pushes the new certificate to Microsoft 365. Wait approximately five minutes for the changes to propagate, then test a login in a fresh incognito window.

    Manual updates require PowerShell to renew the Microsoft 365 Single Sign-On certificate.

    If the Microsoft Office 365 application uses manual settings, the administrator must use PowerShell to update Microsoft Entra ID with the new certificate string before activating it in Okta.

    NOTE: Do not activate the new certificate in Okta until the PowerShell command successfully updates Microsoft Entra ID. Activating the certificate too early immediately breaks all Microsoft 365 Single Sign-On logins.

     

    Generate the certificate, extract the metadata, and update Microsoft Entra ID via PowerShell by completing the following actions.

    1. On the Sign On tab of the Microsoft Office 365 application in the Okta Admin Console, scroll to SAML Signing Certificates and select Generate new certificate. Leave the certificate as inactive.
    2. Select View IdP metadata from the Actions menu of the new certificate.
    3. Copy the long text block located inside the <X509Certificate>
    4. tags. Ensure there are no spaces or line breaks in the copied string.
    5. From the left sidebar in the Okta Admin Console, select View Setup Instructions and locate the PowerShell command under the Update the signing certificate section.
    6. Open PowerShell on the local machine and connect to Microsoft Graph as a Microsoft 365 Global Administrator by running the following command: Connect-MgGraph -Scopes Directory.AccessAsUser.All
    7. Paste and run the command from the Okta setup instructions, replacing the placeholder certificate value with the string copied in step three.
    8. Once PowerShell confirms the domain federation update, return to the Okta Admin Console and select Activate on the new certificate.

    To verify the success of either method, open an incognito browser and attempt to log in to portal.office.com. If the session seamlessly redirects to Okta and back to Microsoft 365, the rotation is complete.

    Expand Post
    Selected as Best
This question is closed.
Loading
Update SSO WS-Fed Cert for M365 Clarification