App registration certificate authentication

ritmo2k 811 Reputation points
2024-10-22T19:21:05.59+00:00

I am looking for any official documentation on best practices related to using self-signed certificates for app registration authentication.

Since the issuer is not validated, it is not clear that there are any disadvantages to using a self-signed certificate.

Does anyone know of any official guidance on this matter?

Thanks!

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Answer accepted by question author
  1. Vasil Michev 123K Reputation points MVP Volunteer Moderator
    2024-10-23T07:20:04.5666667+00:00

    If used solely as a secret, there aren't that many disadvantages. It's mainly around the lifecycle of the certificate itself, and being able to enforce some policy in terms of key strength, validity, etc.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Bandela Siri Chandana 3,065 Reputation points Microsoft External Staff Moderator
    2024-10-23T07:11:20.9666667+00:00

    Hi @ritmo2k

    Thank you for posting your query on Microsoft Q&A.

    I understand that you are looking for an official documentation on best practices related to using self-signed certificates for app registration authentication.

    Follow this documentation: Create a self-signed public certificate to authenticate your application

    Since the issuer is not validated, Self-signed certificates are considered unsafe for public-facing websites and applications.

    Screenshot 2024-10-23 121604

    Hope this helps. Do let us know if you have any further queries.


    If this answers your query, do click `Accept Answer` and `Yes` for was this answer helpful. And, if you have any further query do let us know.

    Thanks,

    B. Siri Chandana.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.