A cloud-based identity and access management service for securing user authentication and resource access
Hey Michael, thanks for reaching out!
Unfortunately, once a client secret is created in Entra ID (formerly Azure AD), you can’t “edit” its expiry date—you can only add or remove secrets. That means you can’t shorten the lifetime of your existing 10-year secrets in place. To comply with your new policy:
- Rotate each long-lived secret by creating a new one that meets the allowed maximum (e.g. 24 months).
- You can do this in the portal under “Certificates & secrets,” or via Microsoft Graph: POST /v1.0/servicePrincipals/{id}/addPassword with a payload that includes your desired EndDateTime.
- Update your applications to use the new secret value.
- Once you’ve verified the new secret works, remove the old one:
- Portal: click the ellipsis next to the old secret → Delete.
- Graph API: POST /v1.0/servicePrincipals/{id}/removePassword with the old credential’s keyId.
You can script this across all your app registrations/service principals—Microsoft even provides PowerShell samples to list and rotate expiring secrets in bulk.
As for your rumor about a 7-day grace period when adding a new secret: that only applies to user passwords, not application client secrets. Client secrets are entirely independent. Adding a new secret does not truncate or otherwise change the expiration of any existing secret—they remain valid until their originally configured expiry date.
Hope that clears things up!
References:
https://learn.microsoft.com/graph/api/serviceprincipal-addpassword?view=graph-rest-1.0
https://learn.microsoft.com/entra/identity-platform/how-to-add-credentials