aethercert
Microsoft and Windows Server

Automated certificate renewal for Microsoft AD FS

AD FS certificates are easy to forget and painful when they expire: federated sign-ins stop. The AD FS package renews the service communications, token-signing or token-decrypting certificate, grants the service account access to the key and assigns it in AD FS.

The deployment steps defined in this package's manifest.

At a glance

Package
windows-adfs-target 3.0.0
Compatibility
Windows Server / AD FS >=2016 <2030
Runs from
A Windows agent on the server
Mechanism
PowerShell
Authentication
Local - no remote login
Capabilities
Import certificate and keyGrant key accessUpdate bindingRemove old certificate
Deployment steps
import → grantKeyRead* → assignAdfsCertificate → cleanup*
Rollback
None
Key usage
Server authentication

* conditional step

What it does

The agent on the AD FS server imports the certificate, grants the AD FS service account - typically a gMSA - read access to the private key, and assigns it as the configured AD FS certificate: service communications, token-signing or token-decrypting.

The superseded certificate is removed after the new one is in place, unless you turn clean-up off.

How it runs

  1. 01

    import

    Certificate and key are imported into the machine store.

  2. 02

    grantKeyRead

    The AD FS service account gets read access to the private key.

  3. 03

    assignAdfsCertificate

    The certificate is assigned in AD FS.

  4. 04

    cleanup

    The previous certificate is removed, if enabled.

What you configure

  • AD FS certificate: service communications (default), token-signing or token-decrypting
  • AD FS service account, for example DOMAIN\adfs-gmsa$
  • Certificate store, friendly name and clean-up

Prerequisites

  • A Windows agent on the primary AD FS server
  • A certificate for the federation service name

Limitations

  • One AD FS certificate type per deploy target.
  • Web Application Proxy servers need their own certificate deployment.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Automate Microsoft AD FS

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.