Clarification on Certificate Expiry and Renewal for Microsoft-Managed Domain used in mfa
This is for an enterprise application mfa.contoso.com | SAML-based Sign-on
We recently received an email notification with the following message:
"Please renew your application certificate in Contoso. You’re receiving this notification because your email address is associated with mfa.contoso.ca. The certificate used for single sign-on to mfa.contoso.com is going to expire in 29 days on November 29, 2024, at 8:30 UTC."
Upon investigation, it appears that this certificate is associated with a Microsoft-managed domain, as the URLs and configurations involved are outside our direct control. Here are the key details:
Our own certificate remains valid until April 2025. The only contoso domain referenced in this configuration is mfa.contoso.com, which is a CNAME for external.contoso.com, and this URL redirects to Microsoft’s domain: https://mysignins.microsoft.com/security-info.
We need clarification on the following points:
- Does any action need to be taken by our team to update or renew this certificate?
- If no action is needed, could you confirm any potential impacts on our users once the certificate expires?
Thank you for your assistance.