Reduce expiry dates for existing Client Secrets for App Registrations & Service Principals?

Michael Herold 25 Reputation points
2026-06-19T09:25:26.82+00:00

Hello!

In the past, our organization has generated client secrets for SPNs with a secret expiry date of 10 years in the future. With a policy update, this is no longer allowed. Instead of forcing a large number of customers to replace their secrets right now, is there a way to reduce the expiry date of the existing secrets to conform to the new limit?

On a related note, when you generate a new client secret for a Service Principal which already has exsting (non-expired) secrets, are those other secrets in any way invalidated or their validity shortened? There's a rumor that those get set to 7 days grace period regardless of their previous expiry date, but I couldn't find any mention of this in any of the official Azure documentation.

Thank you!

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Answer accepted by question author
Sridevi Machavarapu 33,820 Reputation points Microsoft External Staff Moderator
2026-06-19T09:36:59.2733333+00:00

Hey Michael, thanks for reaching out!

Unfortunately, once a client secret is created in Entra ID (formerly Azure AD), you can’t “edit” its expiry date—you can only add or remove secrets. That means you can’t shorten the lifetime of your existing 10-year secrets in place. To comply with your new policy:

  1. Rotate each long-lived secret by creating a new one that meets the allowed maximum (e.g. 24 months).
    • You can do this in the portal under “Certificates & secrets,” or via Microsoft Graph: POST /v1.0/servicePrincipals/{id}/addPassword with a payload that includes your desired EndDateTime.
  2. Update your applications to use the new secret value.
  3. Once you’ve verified the new secret works, remove the old one:
    • Portal: click the ellipsis next to the old secret → Delete.
    • Graph API: POST /v1.0/servicePrincipals/{id}/removePassword with the old credential’s keyId.

You can script this across all your app registrations/service principals—Microsoft even provides PowerShell samples to list and rotate expiring secrets in bulk.

As for your rumor about a 7-day grace period when adding a new secret: that only applies to user passwords, not application client secrets. Client secrets are entirely independent. Adding a new secret does not truncate or otherwise change the expiration of any existing secret—they remain valid until their originally configured expiry date.

Hope that clears things up!

References:

https://learn.microsoft.com/answers/questions/5924472/reduce-expiry-dates-for-existing-client-secrets-for-app-registrations-service-principals

https://devblogs.microsoft.com/microsoft365dev/client-secret-expiration-now-limited-to-a-maximum-of-two-years

https://learn.microsoft.com/graph/api/serviceprincipal-addpassword?view=graph-rest-1.0

https://learn.microsoft.com/entra/identity-platform/how-to-add-credentials

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Newest
  1. Vasil Michev 128K Reputation points MVP Volunteer Moderator
    2026-06-19T09:29:36.41+00:00

    Afaik there is no way to reduce the validity period for existing secrets. But creating new ones will not impact them in any way, they continue to be valid until the expiration day. Not sure where you saw that 7-day grace period, but it's news to me.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.