I've replaced the certificate on some app proxy apps, but the site is still loading the msappproxy cert

Matt Chapman 0 Reputation points
2025-01-21T17:16:52.2+00:00

Hi

I've created some enterprise apps and configured them for app proxy.

I also have a wildcard cert for my domain, and have uploaded this cert to the apps

User's image

But, when I go to the site, I get a certificate error and looking at the cert, it's the default *.msappproxy.net one

User's image

I've done this before with no problems, but have replaced the cert as it had expired.

Can anyone help me figure out why the uploaded cert hasn't taken?

Thanks

Matt

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Matt Chapman 0 Reputation points
    2025-03-28T12:31:50.5533333+00:00

    @James Hamil Thank you for the case. This is now resolved.

    The issue boiled down to a change I made to the name of my Azure domain back in December to update my sharepoint URL. This included adding a new "onmicrosoft" domain.

    When adding the app proxy to applications in Entra, the blue banner at the bottom informs to add the CNAME pointing to the new domain (i.e. ilo-newdomain.msappproxy.net), but the CNAME needs to still point to the original domain.image

    Once we changed this, the certificates were identified correctly and the apps loaded correctly.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.