entra1-5 Exercise 3: The Message to Contoso's Administrator ============================================================ BEFORE YOU SEND IT: THREE THINGS TO CHECK YOURSELF -------------------------------------------------- 1. Is anyone else affected? If other clients are fine, the cause is likely specific to Contoso's tenant or its connection. If every client fails, look at your own side and Microsoft's service health first. 2. What do you already know about Contoso's SAML certificate? Your tenant card or register (Chapter 4): when does it expire, and was it renewed recently? Does the thumbprint your system holds match the last one you were given? 3. What does your own system's log say? The exact error for a failed Contoso sign-in at around 09:15 (a signature error, a missing assertion, a mismatched name identifier), plus any ID the error message contains. (Also worth a minute: did anything change on your side at 09:15, such as a release or a certificate update?) A MODEL MESSAGE --------------- Subject: Contoso sign-in to failing since 09:15 today Hello , Since 09:15 this morning, Contoso users can't sign in to through Microsoft sign-in. Other customers are unaffected, and on our side the failure looks like . That points to something in how the connection to your Microsoft Entra tenant is set up, such as the SAML signing certificate. To confirm, we'd like to see, in your Microsoft Entra admin center, the following. We only need to look; we are not asking you to change anything yet. A short screen share would be quickest, or screenshots (please hide anything that looks like a secret; we never need one): 1. Entra ID > Overview > Properties: the Tenant ID. 2. Entra ID > Enterprise apps > > Single sign-on: the "SAML Certificates" section, showing each certificate's status (Active or Inactive), expiry date and thumbprint. 3. Entra ID > Enterprise apps > > Properties: "Enabled for users to sign in?" and "Assignment required?". 4. Entra ID > Enterprise apps > > Sign-in logs: any entries from 09:15 onward, and the Correlation ID of one failure. Do you know whether the SAML certificate was renewed or changed recently? If it was, we may only need to install the matching certificate on our side, which we can do as soon as we have it. If it's helpful, a Reports Reader role for our engineer for a day would let us read the logs ourselves, but a screen share needs no changes to your tenant. Thank you, WHY THIS WORKS AS AN ANSWER --------------------------- The message states the problem in a sentence, names exactly the pages in this chapter's vocabulary, separates "look" from "change", offers the two least-intrusive routes (screen share, a time-limited read-only role), and never asks for a secret. The three prior checks mean you arrive with a hypothesis and don't make the administrator do work you could have done.