KB No. 19: Renewal of the SAML signature certificate on EntraID
Background
This article explains how to renew the SAML signature certificate after receiving an email from Microsoft regarding its expiration.
Prerequisites
Your certificate is expiring, or you have received an email from Microsoft with the following message:
Step 1: Open EntraID
To renew the SAML signature certificate, go to the Single Sign-On > SAML Certificates section of the application and click Edit.

Add a new certificate with a duration of up to three years by clicking New Certificate. A new line will appear below the old certificate with the status " Not applicable."
Step 2: Force the new certificate to be taken into account
The new certificate will be recognized by your Olfeo tenant within 24 hours. However, you can force it to be recognized by manually launching an update from the administration interface.
To do this, go to the Metadata section of the provider in the Authentication tab of your directory, then click Edit, then Update.


Step 3: Activating the new certificate
To activate the new certificate on EntraID and ensure it is taken into account, click on the three dots on the right, then select Set as active certificate. The old certificate will then change to Inactive status.


