Rotate an Office 365 signing certificate for WS-Federation Automatic
Learn how to generate, update, and activate app-level signing certificates for Office 365 integrations that use WS-Federation Automatic as the sign-on method.
About this task
SAML assertions sent from Okta to Office 365 are cryptographically signed using a signing certificate. If your active signing certificate expires, Microsoft rejects all SAML assertions, which blocks user access to Office 365 apps. To avoid service disruptions, ensure that you rotate your signing certificate before it expires, which involves generating and using a new certificate.
Before you begin
- Sign in as a super admin.
- Verify that the sign on method configured for your Office 365 app instance is WS-Federation Automatic. See Configure Single Sign-On for Office 365.
- In the Admin Console, go to .
- Search for and select the Office 365 app integration whose certificate you want to rotate.
- Go to the Sign On tab.
- Click Generate new certificate in the SAML Signing Certificates section.
- Select Activate from the Actions menu of your new signing certificate. This changes the status of the new certificate to Active and sets the status of the previous certificate to Inactive. SSO operations for the app instance now use the new certificate. If desired, you can delete the old certificate by selecting Delete from its Actions menu.
- Wait five minutes for the certificate to take effect. Verify that SSO is functioning correctly by signing in to an Office 365 app with a federated user.