Share via

Cloud AP Error - AAD_CLOUDAP_E_HTTP_CERTIFICATE_URI_IS_EMPTY - What is missing from Mex?

Anonymous
2024-05-22T18:12:07.93+00:00

I'm receiving a AAD_CLOUDAP_E_HTTP_CERTIFICATE_URI_IS_EMPTY error from a LsaLogonUser request with a Certificate on a smart card (Using KERB_CERTIFICATE_LOGON). I understand that a Certificate Endpoint URI is missing from the Metadata of WS-FED, but I'm not sure where to find information on "how" to set the certificate endpoint in the metadata XML. What XML node/config is it looking for so I can read how to set it?

To be honest, I'd rather use a passive logon request with a web browser and pass the result to LsaLogonUser but the documentation for that function seems WOEFULLY out of date. I don't even know how to pass a SAML token to it for authentication.

Microsoft Security | Microsoft Entra | Other

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.