azure ad saml signing certificate expired login failed
For Entra admins and agents keeping SAML SSO healthy. Use when logins fail on an expired signing certificate. Not for config or user-specific errors.
Fix Azure AD SAML login failing on expired signing certificate
TL;DR
Logins fail when the SAML signing certificate in Entra expired and the app still trusts only the old one. Create a new signing certificate in the Entra enterprise app, make it active, and update the app with the new metadata. Then set a calendar reminder before the next expiry.
The error
SAML login failed
Error: The signing certificate has expired. Authentication cannot be completed.Use this skill
Agent? Search Vectle for this error:
curl -s "https://vectle.com/api/v1/search?q=azure ad saml signing certificate expired login failed"Fix it
Step 1: Check the certificate expiry in Entra
Entra admin center -> Identity -> Applications -> Enterprise applications -> [app] -> Single sign-on -> SAML Signing Certificate.Expected: You see the expiry date; it is in the past.
Step 2: Create a new signing certificate
In the same blade, create a new certificate and set it active.Expected: The new certificate shows a future expiry date and active status.
Step 3: Update the app with new metadata
Download the fresh federation metadata XML and import it into the app's SAML configuration.Expected: The app trusts the new certificate.
Step 4: Test login immediately
Run an SP-initiated login as an affected user.Expected: Login succeeds with no certificate error.
Step 5: Set an expiry reminder
Note the new expiry date and set a reminder 30 days before it.Expected: You will rotate before it expires next time instead of during an outage.
When this applies
- SAML logins through Entra fail with an expired certificate error
- Logins worked until a specific date and then all broke at once
- You are doing routine SAML certificate maintenance
When it doesn't
- The certificate is valid but logins still fail (check signature config or the app side)
- Only some users fail (certificate expiry hits everyone)
- You use OIDC rather than SAML (certificates work differently there)
Compatibility
Microsoft Entra ID SAML single sign-on. Enterprise applications blade as of 2026.
Variant phrasings
azure ad saml certificate expired login error
Same fix. Expiry is all-or-nothing, so the blast radius confirms the diagnosis fast.
entra sso signing cert expired
Entra lets you stage the new cert before activating it. Stage early, activate during a quiet window.
saml signing certificate rollover azure
During rollover, publish metadata with both certs if the app supports it, then retire the old one.
Why it happens
SAML responses are signed with the certificate Entra publishes. Apps validate the signature against the certificate they imported. When the certificate expires and nobody rotated it, every signature check fails at once. It is a maintenance lapse, not a protocol problem.
Edge cases
- Some apps cache the metadata for hours; a rotation can take a while to take effect everywhere
- If the app validates the whole chain, an expired intermediate breaks it too, not just the leaf
- Test the new cert with one user before activating it for everyone when the app allows it
If it still fails
- Capture the exact timestamp, the failing username, and the full error from the IdP system log before changing anything else.
- Reproduce with a single test user so you are not debugging a crowd.
- Check the IdP and app status pages; SSO and provisioning outages look exactly like config errors.
- If it worked before, diff the config against the last known good: certificates, URLs, attribute mappings, and credential expiry.
- Open a vendor ticket with the timestamp, the request id if there is one, and redacted config. Never send secrets or private keys.
Prevention
- Track certificate and credential expiry with alerts, not memory.
- Run a synthetic login per SSO app daily so breakage pages you, not a user.
- Document attribute mappings where the next admin will actually find them.
- Test provisioning with a single user before bulk changes.
- Review app assignments quarterly; stale assignments cause half of provisioning errors.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstaOGC4aXpbjP9oOrZvMTLQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.