Certificates
The Certificates section displays and manages the public key credentials associated with an application. This page is part of the application detail view and is accessible from the left-hand navigation.
- For App Registrations, the section is called Certificates.
- For Enterprise Applications configured for SAML, the section is called SAML certificates.
While the purpose of the certificates may differ, the layout and interaction model are consistent.
Page Layout
The page is divided into two main areas:
- Left navigation: Allows switching between Overview, Certificates, Secrets, Owners, and Settings.
- Main content area: Displays a table listing the certificates associated with the selected application.
A primary action button is displayed in the top-right corner of the page when applicable.
Certificates Table
Certificates are presented in a tabular format. Each row represents a single certificate.
All columns are:
- Sortable, by clicking on the column header
- Filterable, allowing you to quickly narrow down results
Columns
| Column | Description |
|---|---|
| Description | A human-readable label provided when the certificate was added. |
| Thumbprint | The certificate thumbprint, when available. |
| Certificate ID | The unique identifier assigned by Microsoft Entra ID. |
| Task status | Indicates the current status of the task associated with the certificate (for example, New or In progress). |
| Assigned to | Shows the user currently responsible for the certificate task, if assigned. |
| Expiration | Displays the expiration date with a visual status indicator (valid, expiring, or expired). |
Expiration values are visually highlighted to help users quickly identify certificates that require attention.
Row Actions
Each certificate row includes three action icons on the right:
-
Assign / open task
Opens the task side panel, allowing you to:- Assign the task to yourself or another user
- Update the task status
- Add comments
- Review certificate metadata (ID and expiration)
-
Download certificate
Downloads the certificate's public key. See Downloading a certificate. -
Delete certificate
Removes the certificate from the application. A confirmation step is required before deletion.
Adding a Certificate (App Registrations)
For App Registrations, an Add certificate button is available in the top-right corner of the page.
When clicked, a side panel opens where you can:
- Upload a public key certificate file
Supported formats:.cer.pem.crt
- Optionally provide a description to help identify the certificate
- Confirm the action using Let's do it
The certificate is added immediately and appears in the table.
Downloading a Certificate
Every certificate row has a Download action, so you can collect a certificate's public key without opening the Azure portal.
Only the public key is downloaded. Microsoft Entra ID never returns a private key after a certificate has been uploaded, so a downloaded file cannot be used to authenticate as the application.
What happens when you select it depends on the application:
- For an app registration, the certificate downloads immediately as Base64 text.
- For a SAML enterprise application, a menu opens so you can pick the format the other system expects.
Available formats
| Format | File | Use it for |
|---|---|---|
| Base64 certificate | .cer | The text form most tools and portals accept. |
| PEM certificate | .pem | The same key wrapped in BEGIN CERTIFICATE and END CERTIFICATE lines, expected by many Linux and open-source tools. |
| Raw certificate | .cer | The binary DER form. |
| Federated certificate XML | .xml | SAML federation metadata, ready to hand to a service provider. |
Permissions
Download is available to anyone who may already manage the application's credentials — an administrator, an application owner, or a sponsor granted credential permissions.
If you do not have that permission the action is visible but disabled, and explains why when you hover over it.
Task Side Panel
Clicking the task action icon opens a side panel with task details.
From this panel, you can:
- Assign the task to yourself or another user
- Change the task status
- View comments (application owners and admins can also add or modify them)
- View read-only certificate information such as:
- Certificate ID
- Expiration date
Only the assigned user receives notifications related to the task.
SAML Certificates (Enterprise Applications)
For Enterprise Applications that use SAML authentication, this section is labeled SAML certificates.
Key Differences
- Certificates are read-only in EasyLife 365 Identity
- No Add or Delete actions are available
- Download is available, and offers all four formats described above
- Certificates are managed externally through SAML federation or identity provider configuration