Already a NinjaOne customer? Log in to view more guides and the latest updates.

NinjaOne Identity Access Management: Renew or Update an Expiring SAML Certificate

Topic

This article explains how to renew or update a Security Assertion Markup Language (SAML) certificate for access to NinjaOne.

Environment

  • NinjaOne Identity Access Management (IAM)
  • NinjaOne Integrations

Description

Occasionally, an older SAML certificate configured for an enterprise application will expire and no longer allow users to log in to NinjaOne with their single sign-on (SSO) accounts. The renewal process in NinjaOne is similar across all Identity Providers (IdPs), though there are some exceptions. We recommend you review the documentation from the IdP that you use to ensure understanding when generating or renewing a SAML certificate.

NinjaOne does not support SSO via identity providers with expired SAML certificates. Customers who have not updated their SAML certificate before their region's release date will lose the ability to log in to NinjaOne through their identity provider. A NinjaOne System Administrator role must update any expired or expiring SAML metadata before your region's 14.0 release date.

Tentative release dates for each region are as follows:

RegionDate (Tentative)
CA (ca.ninjarmm.com)2026-06-16
OC (oc.ninjarmm.com)2026-06-17
EU (eu.ninjarmm.com)2026-06-24
US2 (us2.ninjarmm.com)2026-07-08
NA (app.ninjarmm.com)2026-07-15

For this article, we will use Microsoft Entra ID as an example. For your convenience, refer to the following external resources to learn how to manage certificates for other IdPs compatible with NinjaOne:

Update Metadata for an Expired SAML Certificate

Updating the metadata for your IdP will invalidate the metadata currently on file in NinjaOne. Attempts to use SSO to log in with that IdP will fail until you complete the update steps below.

You cannot update a certificate until it's within a 30-day window of expiration, regardless of when you receive the expiration notification.

To update the metadata in NinjaOne for your IdP, perform the following steps:

  1. Log in to NinjaOne as a System Administrator. 
  2. Navigate to AdministrationAccountsIdentity providers.
  3. Select the IdP account with the expiring certificate.
  4. Click Update metadata in the notification banner.
Figure 1: Update metadata for an expired certificate (click to enlarge)
  1. Open a separate browser tab and log in to your Microsoft Entra ID account.
  2. Navigate to Enterprise apps and select the NinjaOne SSO application.
  3. Open SAML Certificates and click Edit.
  4. Select New Certificate and then use the following table to complete the applicable fields.

    FieldData
    Signing OptionSign SAML assertion
    Signing AlgorithmSHA-256
  5. Click Save.
  6. Click the actions menu icon and select Make certificate active
  7. Refresh the page and review changes.
Figure 2: Create a new certificate and make it active in Entra ID (click to enlarge)
  1. Navigate to the SSO section of the Enterprise application in Entra ID and copy the App Federation Metadata URL.
  2. Return to the browser tab with your NinjaOne account open to the IdP page.
  3. Paste the copied data into the Import metadata from field and then click Test connection.
Figure 3: Import metadata from IdP URL (click to enlarge)
  1. When the connection succeeds, click Save.

If you require additional assistance, refer to NinjaOne Support: Submitting and Viewing Support Requests in NinjaOne.

Additional Resources

To learn more about NinjaOne IAM, refer to NinjaOne Identity Access Management (IAM): Resource Catalog.

FAQ

Next Steps