Azure SAML authentication: validate identity provider certificate. (best pratices)

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Azure SAML authentication: validate identity provider certificate. (best pratices)

L2 Linker


We have configured SAML on our portal and gateway.  By default Microsoft generates a self signed certificate that is valid for 3 years for every Enterprise application you create.

Is this secure enough to use the default self signed one and not validate it on my gateway/portal leave the check unmarked.

According to this article it should be save if you are running the correct version of Panos.

Securing your SAML Deployments - Knowledge Base - Palo Alto Networks

CVE-2020-2021 PAN-OS: Authentication Bypass in SAML Authentication (


We could generate a certificate from our Internal PKI and upload this in Azure. 

What is the best pratice aroudn this.



Cyber Elite
Cyber Elite

Hi there.. I think with today's modern PANOS, this not going to be an issue. We routinely do SAML cert setups in our PS organization and the Validate Cert is always disabled. 

Hope this helps.

Help the community: Like helpful comments and mark solutions
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!