SSO Certificate Replacement for expiring Entra SSO
AnsweredI have a customer (Boise Centre) who will be replacing their Production Entra SSO Cert in mid-September. In preparation for this, we will be generating a test SSO Cert in the Test environment, but when we do this in Production, there is concern that when the “Generate SSO Certificate” process kicks off on the client's side, their SSO for Enterprise will, effectively, be down until the new SSO Cert is applied on our side.
Does anyone have any experience in how long this takes? Any advice on working with Support and SRE on expediting this process so the risk of downtime is mitigated or (hopefully) eliminated?
-
If they can't have two active certificates (some IDPs allow this), then it would cause issues on the Momentus-side if they generate the new certificate and it has not been updated on our end. In these scenarios, Support or TS will work with the customer to schedule the certificate go-live for Prod and Momentus will be updated when they generate the new cert.
-
Thank you Mike Schepker. Do you know if Entra allows that?
-
I believe so, but that may also be a policy-related setting if not a hard setting, so even if Entra allows it, they might not be able to. Someone else may know more about the actual IDP-side of things. Support doesn't ever log into the customer's IDP so we're not familiar with the settings of each one.
Please sign in to leave a comment.
Comments
3 comments
Date Votes