Renew your Entra ID client secret

Replace your Microsoft Entra ID client secret before it expires so syncing and Microsoft sign-in keep working.

PlansProPremiumCompare plans

ForAdmins

On this page

The client secret that connects CloudCard to Microsoft Entra ID has an expiry date set in Azure. When it expires, CloudCard stops syncing your directory. If your organisation uses Microsoft sign-in, your staff also can’t sign in with their Microsoft account until you renew it.

How CloudCard warns you

CloudCard counts down from the day you saved the secret, using the expiry you chose under Client secret expires in.

  • By email: your organisation’s active admins get an email 30, 14, 7 and 1 day before the secret expires, and again if it does expire. The subject says how many days are left.
  • In CloudCard: the Microsoft Entra ID page shows Secret expires in with the number of days, or Secret expired, plus a panel explaining what to do.

The Client secret expires date is shown under Connection details on the Microsoft Entra ID page.

Renew the secret

In the Azure portal:

  1. Go to App registrations and open your CloudCard app.
  2. Under Certificates & secrets, create a new client secret. Note the expiry you choose.
  3. Copy the new secret’s Value straight away.

In CloudCard:

  1. Open the Microsoft Entra ID page. The Update the connection button in the warning email takes you straight there, or go to Team Members, click Add Users and choose Microsoft Entra ID import.
  2. Click Connection setup.
  3. Paste the new value into Client secret value.
  4. Set Client secret expires in to the expiry you chose in Azure.
  5. Click Update.

CloudCard checks the new secret with Microsoft. If it works, you’ll see “Credentials updated”. The status goes back to Connected and the countdown starts again from today.

Once CloudCard is using the new secret, you can delete the old one in Azure.

Good to know

  • If the secret has already expired, renewing it fixes the connection. Nothing in CloudCard is deleted while it’s broken.
  • If you see “Invalid credentials”, check you copied the secret’s Value, not its Secret ID.
  • If the expiry date in CloudCard doesn’t match Azure, change Client secret expires in and click Update. You don’t need a new secret for that.

For error messages such as “The client secret may have expired”, see “The client secret may have expired”.

Still stuck?

Send us a message and we'll know which article you were reading. Or email [email protected].

Contact support