When a SAML certificate used for your SSO integration expires, users may be unable to sign in to NinjaOne through SSO. To re-establish authentication, you must renew the certificate in your identity provider and upload the updated metadata to NinjaOne.
Step 1: Access the NinjaOne App in Entra ID
- Go to the Microsoft Entra Admin Center.
- Sign in with an admin account.
- From the left menu, select Enterprise apps.
- Find and open your NinjaOne SAML app (e.g., NinjaOne SSO).

Step 2: Generate and Activate a New SAML Certificate
- In the app’s sidebar, go to Single sign-on.
- Under SAML Certificates, select Edit.
- Click New Certificate, then Save to generate it.
- After the new certificate is created, select … (More options) and choose Make active to activate it.
- Once the certificate is active, Download the Federation Metadata XML file.

Step 3: Update the Certificate in NinjaOne
- Sign in to your NinjaOne account as an administrator.
- Go to Administration > Accounts > Identity Providers.
- Select your existing Entra/NinjaOne SSO configuration.
- Click Update metadata in the banner at the top of the page.
- In the Upload metadata dialog, choose File > Choose XML file, and upload the new Federation Metadata XML file downloaded from Entra ID.
- Click on Test connection to verify the new SAML metadata.
- Once the test is successful, click Save to complete the update.
After saving, confirm that the certificate expiration date and metadata details have been refreshed to reflect the new Entra ID configuration.

