You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在PowerShell中更新联合身份验证O365的idp-signing.crt证书

在启用联合身份验证的Microsoft 365环境中更新IDP签名证书

要更新Microsoft 365联合身份环境中的IDP签名证书(idp-signing.crt),可通过以下PowerShell操作完成:

操作步骤

  1. 加载本地证书文件
    将目标签名证书加载到PowerShell变量中,替换路径为证书实际存放位置:

    $cert = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2("C:\Users\test-win\Documents\idp-signing.crt")
    
  2. 转换证书为Base64格式
    Microsoft 365要求签名证书以Base64编码格式传入,执行命令完成转换:

    $certData = [system.convert]::tobase64string($cert.rawdata)
    # 可选:输出转换后的内容,用于验证证书编码是否正确
    $certData
    
  3. 执行联合身份配置更新
    使用Set-MsolDomainAuthentication命令完成证书更新,注意替换所有占位符为你的实际环境参数:

    Set-MsolDomainAuthentication –DomainName $dom `
        -FederationBrandName $fedBradName -Authentication Federated `
        -PassiveLogOnUri $url -SigningCertificate $certData `
        -IssuerUri $uri -ActiveLogOnUri $ecpUrl -LogOffUri $logoutUrl `
        -PreferredAuthenticationProtocol SAMLP
    

注意事项

  • 操作前需安装并连接MSOnline PowerShell模块,通过Connect-MsolService完成管理员身份验证。
  • 所有占位变量(如$dom为你的联合域名、$url为IDP被动登录地址等)必须替换为实际值,否则命令会执行失败。
  • 建议先通过Get-MsolDomainAuthentication -DomainName $dom导出当前联合身份配置,作为备份。

内容的提问来源于stack exchange,提问作者Tuwan J

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 17:22:12