Fix TLS Certificate Errors During Microsoft Entra Pass-Through Authentication
Question details
Users experience a TLS connection failure to servicebus.windows.net because the system cannot verify the certificate's validity.
- Product
- Microsoft Entra
- Device & OS
- not provided
- Scenario
- Setting up or running Microsoft Entra Pass-Through Authentication (PTA) in a corporate network environment.
- Observed behavior
- The connection fails with an error stating the remote certificate is invalid, which happens because the authentication agent cannot reach the Certificate Revocation List (CRL) URL over port 80.
Verify that your corporate firewall, proxy server, and network security groups are configured to allow outbound HTTP traffic.
Allow Outbound Port 80 for CRL Checking
Configure your network infrastructure to permit the Microsoft Entra authentication agent to communicate over port 80 to access Microsoft's Certificate Revocation List URLs.
Microsoft Entra Pass-Through Authentication relies on secure TLS connections to servicebus.windows.net. Before this secure connection is established, the system must verify that the TLS certificate has not been revoked. This verification is done by downloading a Certificate Revocation List (CRL).
Because CRLs are always fetched via unencrypted HTTP, your servers must have unrestricted outbound access to the internet over port 80 specifically for these Microsoft CRL endpoints.
Review your firewall or proxy server logs for the server hosting the Pass-Through Authentication agent to identify any blocked outbound HTTP (port 80) requests.
Update your firewall or proxy rules to allow outbound port 80 traffic to Microsoft's CRL distribution points, such as crl3.digicert.com, crl4.digicert.com, and other endpoints listed in the official Microsoft Entra PTA network requirements.
Open the Windows Services console (services.msc), locate the 'Microsoft Entra Connect Authentication Agent' service, and restart it to force a new connection attempt.
Open the Microsoft Entra admin center, navigate to 'Hybrid management', and check the status of your Pass-Through Authentication agents to ensure they are marked as 'Active'.

Simplify Your Workflow with WPS Office
While resolving complex enterprise infrastructure and Microsoft Entra authentication issues can take time, your daily document productivity shouldn't be interrupted. WPS Office offers a free, lightweight, and highly compatible alternative to Microsoft Office that works seamlessly without complex active directory dependencies.
- 1. Download the Installer: Visit the official WPS website and download the free installation package for your operating system.
- 2. Install the Software: Run the installer and follow the simple on-screen instructions to set up WPS Office in minutes.
- 3. Open Your Files: Launch WPS Office and open your existing Microsoft Office documents (.docx, .xlsx, .pptx) to continue working immediately.

Frequently Asked Questions
Can I use HTTPS (Port 443) for Certificate Revocation List checks instead?
No. CRL checks are strictly performed over HTTP (Port 80). Using HTTPS would require validating a certificate to download the list used for validating certificates, creating a circular dependency that prevents the connection.
How do I test if my server can reach the CRL URLs?
You can open a web browser on the server hosting the authentication agent and attempt to directly navigate to the Microsoft CRL URLs over HTTP. If a file downloads successfully, port 80 is open for that endpoint.
Will fixing this resolve the 'remote certificate is invalid' error?
Yes, in the context of Microsoft Entra Pass-Through Authentication, this error almost always indicates that the agent cannot verify the certificate's revocation status due to a blocked port 80.
Do I need to reboot the server after updating firewall rules?
A full server reboot is usually not necessary. Simply restarting the 'Microsoft Entra Connect Authentication Agent' service from the Windows Services console will initiate a new connection attempt.




