logo
search
Windows Integration Errors

Fix TLS Certificate Errors During Microsoft Entra Pass-Through Authentication

Rana GarciaRana Garcia Oct 1, 2026 869 views

Question details

Users experience a TLS connection failure to servicebus.windows.net because the system cannot verify the certificate's validity.

Product
Microsoft Entra
Device & OS
not provided
Scenario
Setting up or running Microsoft Entra Pass-Through Authentication (PTA) in a corporate network environment.
Observed behavior
The connection fails with an error stating the remote certificate is invalid, which happens because the authentication agent cannot reach the Certificate Revocation List (CRL) URL over port 80.
Before you start

Verify that your corporate firewall, proxy server, and network security groups are configured to allow outbound HTTP traffic.

Solution 1Recommended

Allow Outbound Port 80 for CRL Checking

Configure your network infrastructure to permit the Microsoft Entra authentication agent to communicate over port 80 to access Microsoft's Certificate Revocation List URLs.

Microsoft Entra Pass-Through Authentication relies on secure TLS connections to servicebus.windows.net. Before this secure connection is established, the system must verify that the TLS certificate has not been revoked. This verification is done by downloading a Certificate Revocation List (CRL).

Because CRLs are always fetched via unencrypted HTTP, your servers must have unrestricted outbound access to the internet over port 80 specifically for these Microsoft CRL endpoints.

1
Identify Blocked Traffic

Review your firewall or proxy server logs for the server hosting the Pass-Through Authentication agent to identify any blocked outbound HTTP (port 80) requests.

2
Whitelist CRL Endpoints

Update your firewall or proxy rules to allow outbound port 80 traffic to Microsoft's CRL distribution points, such as crl3.digicert.com, crl4.digicert.com, and other endpoints listed in the official Microsoft Entra PTA network requirements.

3
Restart the Agent Service

Open the Windows Services console (services.msc), locate the 'Microsoft Entra Connect Authentication Agent' service, and restart it to force a new connection attempt.

4
Verify Connection Status

Open the Microsoft Entra admin center, navigate to 'Hybrid management', and check the status of your Pass-Through Authentication agents to ensure they are marked as 'Active'.

Allow Outbound Port 80 for CRL Checking
Why Port 80?: Certificate Revocation Lists are intentionally distributed over HTTP (Port 80) rather than HTTPS (Port 443) to prevent circular dependency errors during the certificate validation process.
Free Microsoft Office alternative

Simplify Your Workflow with WPS Office

While resolving complex enterprise infrastructure and Microsoft Entra authentication issues can take time, your daily document productivity shouldn't be interrupted. WPS Office offers a free, lightweight, and highly compatible alternative to Microsoft Office that works seamlessly without complex active directory dependencies.

  1. 1. Download the Installer: Visit the official WPS website and download the free installation package for your operating system.
  2. 2. Install the Software: Run the installer and follow the simple on-screen instructions to set up WPS Office in minutes.
  3. 3. Open Your Files: Launch WPS Office and open your existing Microsoft Office documents (.docx, .xlsx, .pptx) to continue working immediately.
Excellent compatibility with Microsoft Word, Excel, and PowerPoint formats.Lightweight installation with a minimal footprint on your system resources.Familiar user interface ensuring a seamless migration with zero learning curve.Built-in PDF editing and document management tools.
microsoft office alternative - wps office

Frequently Asked Questions

Can I use HTTPS (Port 443) for Certificate Revocation List checks instead?

No. CRL checks are strictly performed over HTTP (Port 80). Using HTTPS would require validating a certificate to download the list used for validating certificates, creating a circular dependency that prevents the connection.

How do I test if my server can reach the CRL URLs?

You can open a web browser on the server hosting the authentication agent and attempt to directly navigate to the Microsoft CRL URLs over HTTP. If a file downloads successfully, port 80 is open for that endpoint.

Will fixing this resolve the 'remote certificate is invalid' error?

Yes, in the context of Microsoft Entra Pass-Through Authentication, this error almost always indicates that the agent cannot verify the certificate's revocation status due to a blocked port 80.

Do I need to reboot the server after updating firewall rules?

A full server reboot is usually not necessary. Simply restarting the 'Microsoft Entra Connect Authentication Agent' service from the Windows Services console will initiate a new connection attempt.