Automated certificate renewal for Microsoft AD FS
AD FS certificates are easy to forget and painful when they expire: federated sign-ins stop. The AD FS package renews the service communications, token-signing or token-decrypting certificate, grants the service account access to the key and assigns it in AD FS.
package windows-adfs-target 3.0.0
importgrantKeyReadwhen configuredassignAdfsCertificatecleanupwhen configured
At a glance
- Package
windows-adfs-target 3.0.0- Compatibility
Windows Server / AD FS >=2016 <2030- Runs from
- A Windows agent on the server
- Mechanism
- PowerShell
- Authentication
- Local - no remote login
- Capabilities
- Import certificate and keyGrant key accessUpdate bindingRemove old certificate
- Deployment steps
- import → grantKeyRead* → assignAdfsCertificate → cleanup*
- Rollback
- None
- Key usage
- Server authentication
* conditional step
What it does
The agent on the AD FS server imports the certificate, grants the AD FS service account - typically a gMSA - read access to the private key, and assigns it as the configured AD FS certificate: service communications, token-signing or token-decrypting.
The superseded certificate is removed after the new one is in place, unless you turn clean-up off.
How it runs
- 01
import
Certificate and key are imported into the machine store.
- 02
grantKeyRead
The AD FS service account gets read access to the private key.
- 03
assignAdfsCertificate
The certificate is assigned in AD FS.
- 04
cleanup
The previous certificate is removed, if enabled.
What you configure
- AD FS certificate: service communications (default), token-signing or token-decrypting
- AD FS service account, for example DOMAIN\adfs-gmsa$
- Certificate store, friendly name and clean-up
Prerequisites
- A Windows agent on the primary AD FS server
- A certificate for the federation service name
Limitations
- One AD FS certificate type per deploy target.
- Web Application Proxy servers need their own certificate deployment.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Microsoft and Windows Server
Documentation
Automate Microsoft AD FS
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.