When adding a new SAML2 signing certificate in Azure AD (Entra ID) or another identity provider, follow these steps:
Add the new certificate in Azure AD alongside the existing certificate. Do not make the new certificate active yet.
Wait at least until the next 06:00 UTC. At that time, we automatically refresh your SAML metadata and will trust both certificates.
Activate the new certificate as the primary signing certificate in Azure AD.
Remove the old certificate only after you've confirmed that login works correctly with the new certificate.
Important: If you activate the new certificate before 06:00 UTC (before we've refreshed the metadata), SAML login attempts will fail until the next refresh occurs.
