Original Message:
Sent: 07-11-2024 17:36
From: Brian Jones
Subject: Microsoft Azure AD SSO Certificate expiring soon - how to renew?
FYI @Vaun McCarthy or others who are curious regarding his last point. It appears you can have multiple SSO certs on the Genesys side, but the system will only honor the active one. When our Azure team activated the new cert, it/they deactivated the old cert. So once the new cert was activated, we went back into Genesys (using SSO successfully from an incognito browsing session as a part of our testing) and [proactively] deleted the old cert to keep things clean.
We just went through this process today without an outage or disruption to users, and [thankfully] everything has gone well since.
------------------------------
Brian T. Jones | Ascension | Senior Specialist - Technology
------------------------------
Original Message:
Sent: 02-25-2024 19:06
From: Vaun McCarthy
Subject: Microsoft Azure AD SSO Certificate expiring soon - how to renew?
Hey Jeff
Rough idea of what I've done/recommend.
- Definitely do this out of hours (if possible)
- Get new certificate exported from the SSO/SAML app in Azure
- If your org is set to be SSO only, as a precaution turn that off and make sure you can get in using Genesys authentication in case something goes wrong
- Import new certificate into SSO settings in Genesys Cloud
- Test SSO
I don't recall if you can keep multiple certs on the Genesys side (think you can for SIP but not for auth). It's possible on Azure it will continue to honour the old certificate until you import the new one and start using it. Still worth doing out of hours. I think we pretty much had to cross our fingers when we went through it but didn't hit any issues.
------------------------------
Vaun McCarthy