azure login certificate validation failed

Dave Murray 0 Reputation points
2025-05-20T12:04:58.59+00:00

Trying to use two azure logins I now cannot access one due to the following error - certificate validation failed

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Raja Pothuraju 23,465 Reputation points Microsoft External Staff Moderator
    2025-05-20T23:51:55.5766667+00:00

    Hello @Dave Murray,

    The "certificate validation failed" error typically occurs when the user is enabled for the Certificate-based Authentication (CBA) method in the tenant or when a Conditional Access policy is configured to require CBA exclusively. Please refer to the screenshot below so we're on the same page.

    User's image

    Based on your description, it appears that you haven’t explicitly enabled CBA for any users in the tenant, but your colleague is still encountering this issue.

    There are two areas we need to verify:

    Authentication Methods Policy Please check whether the CBA method is enabled in your tenant and if any users are included in that policy. You can navigate to: Microsoft Entra ID → Security → Authentication methods → Certificate-based Authentication

    If CBA is in use, try disabling it for troubleshooting purposes.

    User's image

    Conditional Access Policies Review the Conditional Access policies applied to the user's account and check whether any policy is configured with “Require authentication strength” as a grant control. If such a configuration exists and includes a requirement for CBA, it could explain the issue.

    User's image

    Please verify the above steps. If the user is not targeted by either of these configurations and is still encountering the certificate validation error, we can investigate this further offline.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.