Renew an Expiring Microsoft Entra ID SSO Signing Certificate for OnBoard

Donald McColly
Donald McColly
  • Updated

Overview

This article explains how to renew an expiring Security Assertion Markup Language (SAML) Single Sign-On (SSO) signing certificate in Microsoft Entra ID (formerly Azure Active Directory) and reconnect OnBoard to use the new certificate.

When the signing certificate changes, OnBoard must be configured again so it can read the updated identity provider (IdP) metadata and trust the new certificate.

Following these steps helps prevent organization-wide SSO sign-in failures and ensures users can continue accessing OnBoard.

Environment and Requirements

Where does this procedure apply?

This procedure applies to:

  • OnBoard web
  • Settings > Security > Enable SSO
  • SAML-based SSO with Microsoft Entra ID
  • Organizations using Microsoft Entra ID as their identity provider (IdP)

You will need:

  • An OnBoard Organization Administrator
  • A Microsoft Entra administrator with access to the OnBoard Enterprise Application

Symptoms of an Expiring SSO Certificate

How do I know the signing certificate needs to be renewed?

You may need to renew the signing certificate if:

  • Microsoft Entra ID shows that the OnBoard application's SAML signing certificate is approaching expiration.
  • The signing certificate has already expired.
  • Users suddenly cannot sign in using SSO.
  • All organization members receive SSO authentication errors after a certificate change.

Preparation Before Renewing the Certificate

What should I do before starting?

Before making any changes:

  1. Plan a short maintenance window.
    • SSO sign-in will be unavailable from the time SSO is disabled until setup is completed again.
    • During this period, users must sign in with their OnBoard email address and password.
    • Users who do not know their password can use Forgot Password.
  2. Record your current SSO settings.
    • Go to Settings > Security in OnBoard.
    • Write down:
      • Sign-On Domain
      • Display Name
      • IDP Metadata URL
NOTE: OnBoard does not retain these values when SSO is disabled.
  1. Complete Steps 2 through 5 in one session.
    • This minimizes user impact and reduces the chance of configuration issues.

Make SSO Optional Before Making Changes

Why should SSO be made optional first?

Making SSO optional first ensures administrators can still access OnBoard using email and password while the SSO configuration is being updated.

Step 1: Change the Sign-In Requirement

  1. Go to Settings > Security.
  2. Under Sign-in Requirement, select SSO Optional.

This keeps traditional OnBoard authentication available during maintenance.

Disable the Existing SSO Configuration

How do I disable SSO in OnBoard?

Disabling SSO removes the current SSO configuration from OnBoard without changing anything in Microsoft Entra ID.

Step 2: Disable SSO

  1. Turn off the Enable SSO toggle.
  2. In the Disable SSO Setting dialog, select Disable.
NOTE: This only removes the configuration in OnBoard. No changes are made to Microsoft Entra ID.

Activate the New Signing Certificate in Microsoft Entra ID

How do I create and activate a new certificate?

Creating and activating a new certificate allows Microsoft Entra ID to begin signing authentication requests with the updated certificate.

Step 3: Update the Certificate in Entra ID

  1. Sign in to the Microsoft Entra Admin Center.
  2. Open Enterprise Applications.
  3. Select your OnBoard application.
  4. Select Single Sign-On.
  5. In the SAML Certificates section, select Edit.
  6. Create a new certificate.
  7. Make the new certificate the Active certificate.
  8. Save the changes.

Verify the SAML Configuration

Confirm the following values in Basic SAML Configuration:

Identifier (Entity ID): https://onboardmeetings.com

Reply URL (Assertion Consumer Service URL): https://auth.onboardmeetings.com/Home/Saml2AssertionConsumerService

Obtain the Updated Metadata URL

  1. In SAML Certificates, locate the App Federation Metadata URL.
  2. Copy the URL for use in the next step.

Reconfigure SSO in OnBoard

How do I reconnect OnBoard to the new certificate?

Reconfiguring SSO causes OnBoard to read the updated identity provider metadata and trust the new signing certificate.

Step 4: Enable and Configure SSO Again

  1. Go to Settings > Security.
  2. Turn on Enable SSO.
  3. Select Set Domain.
  4. Enter:
    • Your email domain
    • Your email address
  5. Enter the verification code sent to your email.
  6. Select Configure Provider.
  7. Enter the Display Name.
  8. Paste the App Federation Metadata URL into IDP Metadata URL.
  9. Select Set Configuration.

Validate the New Configuration

How do I test the updated SSO connection?

Testing confirms that the new certificate is working correctly before enforcing SSO requirements.

Step 5: Test SSO

  1. Open a private or incognito browser window.
  2. Sign in using SSO.
  3. Verify that:
    • Authentication succeeds.
    • You are directed to the correct organization.
    • No certificate or SAML errors occur.

Re-Enable Mandatory SSO

How do I require SSO again?

If your organization previously required SSO, you can restore the requirement after testing is successful.

Step 6: Set SSO Required

  1. Confirm you are currently signed in through SSO.
    • OnBoard only allows SSO Required to be enabled while signed in using SSO.
  2. Go to Settings > Security.
  3. Under Sign-in Requirement, select SSO Required.

Why This Process Is Necessary

Why does OnBoard need to be configured again after certificate renewal?

OnBoard reads the identity provider's signing certificate from the metadata provided during SSO setup.

When Microsoft Entra ID begins using a new certificate, OnBoard does not automatically retrieve the updated certificate. Running the SSO setup process again causes OnBoard to download the latest metadata and trust the new certificate.

Troubleshooting

What if sign-in still fails after reconfiguring SSO?

If authentication fails after completing the setup:

  1. Open the Microsoft Entra application's Basic SAML Configuration.
  2. Verify that the Identifier (Entity ID) is exactly: https://onboardmeetings.com
  3. Some older configurations use:  OnBoard
  4. If the older value is present:

Are user accounts created automatically through SSO?

No.

Users must already exist in OnBoard, and their email address must match the email address sent by Microsoft Entra ID during authentication.

What information should I provide to Support?

Provide:

  • The complete error message
  • A HAR (HTTP Archive) file

For instructions, see:

Related Articles

What additional SSO resources are available?

Frequently Asked Questions (FAQ)

Can I renew the certificate without disabling SSO in OnBoard?

No. OnBoard must be reconfigured to read the updated metadata and signing certificate. Disabling and re-enabling SSO ensures the new certificate is imported correctly.

Will users lose access during the update?

Users cannot sign in with SSO while the configuration is being updated. However, users can still sign in with their OnBoard email address and password while SSO Optional is enabled.

What happens if the certificate expires before I renew it?

Once the certificate expires, SSO authentication may fail for all users because OnBoard can no longer validate authentication requests signed with the expired certificate.

Do I need a new metadata URL after renewing the certificate?

Not always, but you should always copy the current App Federation Metadata URL from Microsoft Entra ID and use it when reconfiguring SSO.

Can I make SSO required immediately after configuration?

Only after successful testing. Verify that SSO authentication works correctly in a private browser session before changing the sign-in requirement back to SSO Required.

Why does OnBoard require a matching email address?

OnBoard links the authenticated Microsoft Entra ID user to an existing OnBoard account based on email address. If the email addresses do not match, authentication may succeed but access to the user account cannot be completed.

How can I avoid future SSO certificate outages?

Monitor the certificate expiration date within Microsoft Entra ID and renew the certificate before it expires. Scheduling renewal during a maintenance window helps prevent unexpected sign-in interruptions.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request

Comments

0 comments

Please sign in to leave a comment.