Entra Application Proxy with Custom Domains - Roadmap for shorter TLS Certificate validity

la-421006 5 Reputation points
2026-07-23T11:49:56.3+00:00

Hello,

With TLS certificate validity periods becoming increasingly shorter, manual certificate replacement for Entra Application Proxy Custom Domains is becoming difficult to sustain operationally.

Today, the only automation option appears to be the Microsoft Graph Beta API, which does not seem to be a fully supported long-term solution.

Is Microsoft planning to introduce native certificate lifecycle automation for Application Proxy custom domains, for example through:

  • ACME integration
  • Azure Key Vault integration
  • Any other automated renewal mechanism

Does anyone face the same challenge and maybe is able to share a way to circumvent this problem? Does Microsoft have anything in the pipeline to address this?

Thanks

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.