Verifying automatic renewal of the PTA Agent certificate

Donald 5 Reputation points
2026-07-23T10:28:56.9666667+00:00

Hello,

We are using Microsoft Entra ID Pass-through Authentication and I would like to verify that the hisconnectorregistrationCA.his.msappproxy.net certificate is being renewed automatically as expected.

According to the documentation, the certificate is renewed automatically approximately 30 days before expiration and is stored in the Network Service certificate store.

Could you please clarify:

  1. How can I view the certificate that is stored in the Network Service certificate store?
  2. Is there a supported method to verify that the automatic renewal process has completed successfully?
  3. Are there specific Event Viewer logs, PowerShell commands, or diagnostic tools that show the current active PTA agent certificate and its expiration date?
  4. How can I confirm which certificate is currently being used by the Pass-through Authentication Agent?
  5. What is the recommended procedure to troubleshoot or manually renew the certificate if automatic renewal does not occur?

We would like to proactively monitor the certificate renewal process and ensure that Pass-through Authentication continues to function without interruption.

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.