TenantID certificate, for VPN MFA expired. How renew?

ivo popelak 21 Reputation points
2020-12-11T12:25:03.1+00:00

Hello,

on server is installed and configured VPN with MFA security (called as Radius and NPS).
On this server was automaticaly created "TenantID" certificate. This certificate expired a few days ago and now is imposible connect to VPN.
In Event log: Event ID: 20271.
Information about certificate on web: "server must be set to automaticly renew certificate before expiration". This wasn't set.

Please, can someone help, how correctly renew "TenantID" certificate now, if actual certificate expired?

Thank you very much
Have a nice day
Ivo

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. AmanpreetSingh-MSFT 56,876 Reputation points Moderator
    2020-12-15T10:32:35.423+00:00

    Hi @ivo popelak · Welcome to Q&A and thank you for your query.

    A self signed certificate gets generated when you run below PS Script as part of initial installation and configuration of NPS extension.
    C:\Program Files\Microsoft\AzureMfa\Config\AzureMfaNpsExtnConfigSetup.ps1

    Please run this script again to get a new certificate generated for this purpose.

    Read more: Configure certificates for use with the NPS extension by using a PowerShell script

    -----------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    5 people found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.