On-Demand Assessment signing certificate expired

Luca Fabbri 156 Reputation points
2022-09-12T20:36:31.73+00:00

Hello,
starting from 1st of September 2022, we are experiencing issues with On-Demand Assessments (Active Directory, Azure Active Directory).
File processed.trace.<GUID>.adassessment.assessmenttrace reports this error:

Method=LoadCertificate Message=Certificate has expired or has no valid root. Thumbprint=8740DF4ACB749640AD318E4BE842F72EC651AD80 Subject=CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US ErrorMessage=Chain Status=NotTimeValid ChainStatusInfo=A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Method=Main Message=Unable to load package. PackagePath=C:\Program Files\Microsoft Monitoring Agent\Agent\Health Service State\Resources\62\AzureAssessment.execpkg

Looking at C:\Program Files\Microsoft Monitoring Agent\Agent\Health Service State\Resources\62\AzureAssessment.execpkg, it seems was signed by a certificate expired on 1st of September 2022:

240226-error.png

240204-image.png

Tasks already performed:

  1. Uninstalled and installed the latest version of Microsoft Monitoring Agent (MMA) v10.20.18067.0 - downloaded from the Log Analytics workspace
  2. Remove-AzureAssessmentTask and Add-AzureAssessmentTask again (I discovered the PowerShell cmdlet doesn't support the -MFA parameter, despite I can found it referenced in Microsoft documentation - so I had to removed the MFA for the Azure AD users used for the Assessment) => same SSL certificate error

Any advice or recommendation to solve this issue ?

Thank you,
Luca

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

5 answers

Sort by: Most helpful
  1. Givary-MSFT 35,626 Reputation points Microsoft Employee Moderator
    2022-09-13T08:16:50.643+00:00

    @Anonymous Thank you for reaching out to us. As I understand you are experiencing issues with On-Demand Assessments (Active Directory, Azure Active Directory)

    Reviewed the documentation for Active Directory On-Demand Assessment and Azure Active Directory On-Demand Assessment

    You need to contact Services Hub and raise a request from this portal https://serviceshub.microsoft.com/gethelp by selecting appropriate option.

    Let me know if you have any further questions.

    1 person found this answer helpful.

  2. Luca Fabbri 156 Reputation points
    2022-09-25T07:51:06.213+00:00

    Hello All,
    the SSL certificate expiration issue was fixed on 23rd Sept by Microsoft.

    Bye,
    Luca

    1 person found this answer helpful.
    0 comments No comments

  3. Limitless Technology 44,766 Reputation points
    2022-09-16T08:28:44.413+00:00

    Hi,

    Thank you for your question and reaching out. My name is Louie and I’d be more than happy to help you with your query.

    I understand that you're experiencing issues with On-Demand Assessments.

    • Is your device in Windows 10 or 11?
    • When was the last time you access this successfully?

    Kindly get back to us. Also, while waiting, you may access this link to get further information that could help you resolve the concern: https://learn.microsoft.com/en-us/services-hub/health/getting-started-ad

    ----------------------------------------------------------------------------------------------------------------------------------

    If the reply was helpful, please don’t forget to Upvote or Accept as answer. Thank you!

    0 comments No comments

  4. shabarinath 1 Reputation point
    2022-09-26T17:21:37+00:00

    Thank you Luca for confirming.

    0 comments No comments

  5. Egan 0 Reputation points
    2025-02-27T17:00:38.3733333+00:00

    Hello,

    i ran into this issue with the AMA On Demand Assessments. Basically all assessments downloaded from the Services Hub to the Data Collector got expired Certificates.

    Is there a solution/workaround for this?

    Thanks!

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.