Description
This article explains the procedure for upgrading (key exchange) the federation domain for customers who have configured federation between Microsoft 365 and Access Control using PowerShell (legacy procedure).
For environments where federation was configured using PowerShell (legacy procedure), we recommend switching the certificate key used for authentication.
By following this procedure, you will gain the following benefits:
Enhanced security
The certificate will be updated to a new one with a longer key length (key size), improving security.Improved user convenience (MFA skip feature)
If multi-factor authentication that meets Microsoft’s requirements is completed on the HENNGE side, duplicate MFA prompts on the Entra ID side can be skipped.
* For more details and conditions, please refer to the following article.
🔗Reference: About Multi-Factor Authentication (MFA) Requests for HENNGE Access Control Integration with Microsoft 365
Content
Preparation (Add Service)
-
Log in to the Access Control admin console and go to [System] – [Connected Services].
-
Check if the following settings exist on the screen.
Display Name: Microsoft
Type: Microsoft
If these exist, proceed to step 7 and beyond.
-
If the settings do not exist, click [Add Connected Service] at the top right of the screen.
-
On the "Add New Service" screen, click [Add Connected Service].
-
Select [Use Preset] – [Microsoft].
-
In "Access Policy Groups Allowed for This Connected Service," turn on [Allow] for the groups that are permitted to access Microsoft 365, then click [Save Changes].
When connecting via PowerShell, "all access policy groups were allowed" by default, so in general, allowing all access policy groups will safely maintain the previous state.
-
Again, from [Connected Services], open the Microsoft settings you just saved, and click [Federated Domains] – [Manage Domains].
When the "Requested Permissions" screen appears, check [Consent on behalf of your organization] and select [Accept].
* If the screen does not appear and you proceed to the next screen, authentication has already been completed, so you can continue as is.When the "Domain Management" screen appears, click [Upgrade] for the target domain whose "Status" is [Federated (legacy procedure)].
-
Confirm that the "Status" of the target domain is now [Federated] (the legacy procedure label is removed), then click [Got it!] to complete the process.
Translation Disclaimer
This article has been automatically translated from the original Japanese version for your convenience.
While we strive to ensure accuracy, we cannot guarantee its reliability or completeness.
In the event of any discrepancies or questions regarding the content, the official Japanese version shall prevail.