Tutorial Manage Certificates For Federated Single Sign On
In brief
The instructions now say to verify notification email addresses configured through Microsoft Graph or PowerShell in the Microsoft Entra admin center. Opening the SAML certificate experience can initialize notification registration for custom signing certificates.
What Entra admins need to know
Administrators should verify the notification email address in the app’s SAML settings; otherwise certificate expiration emails might not be sent.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
You receive the notification email from [email protected]. To avoid the email going to your spam location, add this email to your contacts.
and verify that the Notification email address is configured correctly in the SAML Certificates section.
For applications that use a custom SAML signing certificate, opening the SAML certificate experience in the Microsoft Entra admin center should initialize certificate notification registration if it does not already exist. Notification registration and certificate information may take time to refresh. Administrators should verify certificate notification settings well in advance of certificate expiration. If the SAML settings aren’t verified in the admin center, certificate expiration notification emails might not be sent.
Renew a certificate that is set to expire soon
@@ -110,9 +110,10 @@ You can add up to five email addresses to the Notification list (including the e You receive the notification email from [email protected]. To avoid the email going to your spam location, add this email to your contacts. > [!NOTE]-> If notification email address configuration is completed programmatically using Microsoft Graph or PowerShell, administrators should also save the notification email settings in the Microsoft Entra admin center. -> Go to **Enterprise applications** > **[Application]** > **Single sign-on** > **SAML**, select **Edit** in the **SAML Certificates** and under **Notification email** section, re-confirm the notification email address, and then select **Save**.-> If the SAML settings aren’t re-saved in the admin center, certificate expiration notification emails might not be sent.+> If notification email addresses are configured programmatically using Microsoft Graph or PowerShell, administrators should navigate to **Enterprise applications** > **[Application]** > **Single sign-on** > **SAML**+and verify that the **Notification email** address is configured correctly in the **SAML Certificates** section.+> For applications that use a custom SAML signing certificate, opening the SAML certificate experience in the Microsoft Entra admin center should initialize certificate notification registration if it does not already exist. Notification registration and certificate information may take time to refresh. Administrators should verify certificate notification settings well in advance of certificate expiration.+> If the SAML settings aren’t verified in the admin center, certificate expiration notification emails might not be sent. ## Renew a certificate that is set to expire soon 