{"id":1723,"date":"2023-11-25T07:42:38","date_gmt":"2023-11-25T07:42:38","guid":{"rendered":"http:\/\/neu.koetzingit.de\/ungueltiges-zertifikat-des-azure-multi-factor-auth-client\/"},"modified":"2026-06-02T13:32:28","modified_gmt":"2026-06-02T13:32:28","slug":"ungueltiges-zertifikat-des-azure-multi-factor-auth-client","status":"publish","type":"post","link":"https:\/\/www.koetzingit.de\/en\/ungueltiges-zertifikat-des-azure-multi-factor-auth-client\/","title":{"rendered":"Invalid certificate for the Azure Multi-Factor Auth client!?"},"content":{"rendered":"<p><span class=\"dropcapmiddle\">L<\/span>Last week, I received a request from a customer reporting that MFA authentication had suddenly stopped working. The customer then installed the latest NPS MFA extension and ran the MFA troubleshooting script, but found nothing. Ultimately, he asked me for immediate support. A look at the MFA event log revealed a <strong>critical error<\/strong> featuring: \u201e<strong>CLIENT_CERT_IDENTIFIER<\/strong>\u201c and thus a reference to the local certificate on the NPS server. In the personal certificate store, the certificate is associated with the <em>Azure tenant ID<\/em> ...and this was still valid just one day ago! A new certificate for the Azure Multi-Factor Authentication client needs to be generated, but how?<\/p>\n<p><!--more--><\/p>\n<p>Here is the certificate, and to be sure, the \u201eIssuer\" field in the details must read: \"<strong>OU= Microsoft NPS Extension<\/strong>\u201c.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1721\" title=\"MFA Client Certificate\" src=\"http:\/\/www.koetzingit.de\/wp-content\/uploads\/2023\/11\/news-mfa-cert.png\" alt=\"MFA Client Zertifikat\" width=\"370\" height=\"473\" srcset=\"https:\/\/www.koetzingit.de\/wp-content\/uploads\/2023\/11\/news-mfa-cert.png 370w, https:\/\/www.koetzingit.de\/wp-content\/uploads\/2023\/11\/news-mfa-cert-235x300.png 235w\" sizes=\"auto, (max-width: 370px) 100vw, 370px\" \/><\/p>\n<p>The solution is, once again, the <strong>AzureMfaNpsExtnConfigSetup.ps1<\/strong> Run the script to generate a new certificate. This must be done every two years, as the private certificate is not valid for longer than that.<\/p>\n<p>Case closed? No, because instead of a \u201e<strong>Approve\/Deny<\/strong>\u201cA one-time password (OTP) was requested, but it worked. However, the users are the \u201e<strong>Approve\/Deny<\/strong>\u201cwas used to it and wanted it that way again! The customer\u2019s update of the NPS MFA extension resulted in Microsoft, with the newer version,<strong> Force OTP<\/strong>! Fortunately, this can be undone via a registry key. To do this, set the value <code>OVERRIDE_NUMBER_MATCHING_WITH_OTP<\/code> on <code>FALSE<\/code> set it to disable the OTP requirement.<\/p>\n<p>Problem solved? Not quite, because in Entra, the certificate expiration status for the \u201eAzure Multi-Factor Auth Client\u201c was still set to <strong>invalid<\/strong>!? The problem is that the \u201eAzure Multi-Factor Auth Client\u201c enterprise application may have multiple certificates stored, and if even one of the certificates has expired, the status becomes invalid. Therefore, you must <strong>all invalid certificates <\/strong>can be deleted, but how? Using the PowerShell command: <code>Get-MsolServicePrincipalCredential -AppPrincipalId \"981f26a1-7f43-403b-a875-f8b09b8cd720\" -ReturnKeyValues 1<\/code> all certificates can be displayed. Then all expired certificates must be deleted using the Key ID. The command <code>Remove-MsolServicePrincipalCredential -AppPrincipalId \"981f26a1-7f43-403b-a875-f8b09b8cd720\" -KeyID \"d8d60ffe-9991-4c05-960d-29c51a7d4540\"<\/code> then deletes the certificate with the specified KeyID. Once all certificates have been deleted, the status displays \u201e<strong>Current<\/strong>\u201c.\u201d.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1722\" title=\"news-mfa-client-status\" src=\"http:\/\/www.koetzingit.de\/wp-content\/uploads\/2023\/11\/news-mfa-client-status.png\" alt=\"news-mfa-client-status\" width=\"679\" height=\"145\" srcset=\"https:\/\/www.koetzingit.de\/wp-content\/uploads\/2023\/11\/news-mfa-client-status.png 679w, https:\/\/www.koetzingit.de\/wp-content\/uploads\/2023\/11\/news-mfa-client-status-300x64.png 300w\" sizes=\"auto, (max-width: 679px) 100vw, 679px\" \/><\/p>\n<p>That finally resolved the support case for me, but keep in mind that the certificate <strong>every two years<\/strong> needs to be renewed.<\/p>","protected":false},"excerpt":{"rendered":"<p>Letzte Woche hatte ich eine Anfrage eines Kunden, dass die MFA-Authentifizierung pl\u00f6tzlich nicht mehr geht. Der Kunde hat daraufhin die [&hellip;]<\/p>\n","protected":false},"author":1755,"featured_media":1720,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[23],"tags":[345,344,301,300,32,299,342,343,341],"class_list":["post-1723","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-de","tag-azuremfanpsextnconfigsetup-ps1","tag-client_cert_identifier","tag-extension","tag-mfa","tag-microsoft","tag-nps","tag-otp","tag-totp","tag-zertifikat"],"uagb_featured_image_src":{"full":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2023\/11\/news-mfa-cert-1.png",282,360,false],"thumbnail":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2023\/11\/news-mfa-cert-1-150x150.png",150,150,true],"medium":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2023\/11\/news-mfa-cert-1-235x300.png",235,300,true],"medium_large":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2023\/11\/news-mfa-cert-1.png",282,360,false],"large":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2023\/11\/news-mfa-cert-1.png",282,360,false],"1536x1536":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2023\/11\/news-mfa-cert-1.png",282,360,false],"2048x2048":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2023\/11\/news-mfa-cert-1.png",282,360,false],"trp-custom-language-flag":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2023\/11\/news-mfa-cert-1.png",9,12,false]},"uagb_author_info":{"display_name":"Thomas K\u00f6tzing","author_link":"https:\/\/www.koetzingit.de\/en\/author\/thomas-koetzing\/"},"uagb_comment_info":2,"uagb_excerpt":"Letzte Woche hatte ich eine Anfrage eines Kunden, dass die MFA-Authentifizierung pl\u00f6tzlich nicht mehr geht. Der Kunde hat daraufhin die [&hellip;]","_links":{"self":[{"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/posts\/1723","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/users\/1755"}],"replies":[{"embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/comments?post=1723"}],"version-history":[{"count":1,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/posts\/1723\/revisions"}],"predecessor-version":[{"id":1855,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/posts\/1723\/revisions\/1855"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/media\/1720"}],"wp:attachment":[{"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/media?parent=1723"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/categories?post=1723"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/tags?post=1723"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}