To effectively resolve Error AADSTS50003 - No signing key configured , it is important to understand the underlying identity management mechanics. When a user attempts to log into an application configured for SAML-based SSO, Microsoft Entra ID must package the user's identity data into a SAML token. To prove this token genuinely came from your tenant and hasn't been tampered with, Entra ID must sign it using a specific
Understanding Error AADSTS50003 - No signing key configured
To effectively resolve Error AADSTS50003 - No signing key configured , it is important to understand the underlying identity management mechanics. When a user attempts to log into an application configured for SAML-based SSO, Microsoft Entra ID must package the user's identity data into a SAML token. To prove this token genuinely came from your tenant and hasn't been tampered with, Entra ID must sign it using a specific cryptographic key (a certificate)
If you see this error, it simply means your specific Enterprise Application lacks an active certificate to perform this digital signature. This issue frequently occurs within the broader context of Microsoft 365 and Office | Subscription, account, billing | For business | Other administrative tasks, particularly when setting up a new application, migrating from an older identity provider, or when a previously active certificate silently expires. Identifying the root cause ensures you can prevent sudden lockouts during future compliance or security audits
Fixing Error AADSTS50003 - No signing key configured via Entra Admin Center
The steps below target Error AADSTS50003 - No Signing Key Configured in Microsoft Entra and use Enterprise applications > Single sign-on > SAML Certificates as the visible reference point.

- Navigate to the Microsoft Entra admin center (entra.microsoft.com) and log in using an account with at least Cloud Application Administrator privileges
- On the left-hand navigation pane, expand the Identity menu, go to Applications , and click on Enterprise applications . Select the specific application throwing the error
- Under the application's Manage menu on the left, click on Single sign-on . Ensure the SSO mode is currently set to SAML
- Scroll down to Section 3 labeled SAML Certificates and click the Edit pencil icon in the top right corner of that section
- Click the New Certificate button. Leave the default calendar duration or adjust the expiration date as per your company policy, then click Save at the top
- Locate your newly created certificate in the list. Click the three dots (context menu) next to it, and select the command Make certificate active . Confirm the prompt
- Return to the main Single sign-on page, scroll to the bottom section, and click Test to verify the SAML login now completes without the error
How to Verify the Microsoft Entra Result
Validate the change before closing the app: Return to the main Single sign-on page, scroll to the bottom section, and click Test to verify the SAML login now completes without the error A different result usually means the wrong file, account, or Make certificate active was used.
WPS Office: A Free Microsoft Office Alternative for Error AADSTS50003 - No Signing Key Configured in
For local work related to Error AADSTS50003 - No Signing Key Configured in Microsoft Entra, WPS Office is a free Microsoft Office-compatible alternative. It cannot repair a proprietary Microsoft Entra service, add-in, account, or Windows/macOS installation state, so use the verified Microsoft procedure above for the original fault.
While you complete “Error AADSTS50003 - No Signing Key Configured in Microsoft Entra” in Microsoft’s interface, use WPS Writer, Spreadsheets, and PDF for local policy notes, user lists, audit exports, and PDF records; WPS AI can also summarize administrative notes and organize exported data. Because the desktop interface follows familiar document, spreadsheet, presentation, and PDF conventions, most users can move common local work without rebuilding their workflow.

Microsoft Entra FAQs About Error AADSTS50003 - No Signing Key Configured in Microsoft Entra
Does this error affect my entire Microsoft 365 tenant?
No. This error is application-specific. It only affects the individual third-party app integrated via SAML where the certificate is missing or inactive. Other enterprise apps and standard Microsoft 365 services will continue to function normally.
Why did my application suddenly start throwing this error if no one changed the settings?
The most common reason for this sudden failure is certificate expiration. SAML certificates generated in Entra ID typically have a default lifespan (e.g., 3 years). Once that date passes, the key becomes invalid, and you must generate and activate a new one following the primary steps.
How quickly does the new signing key take effect after activation?
Within Microsoft Entra ID, the activation is nearly instantaneous. However, if your third-party application does not automatically poll the App Federation Metadata URL to fetch the new key, you will need to manually upload the new Base64 certificate to the application's admin portal to restore access.
What if the "New Certificate" button is grayed out?
If you cannot click the button, you lack the necessary administrative permissions. You must request a Global Administrator or Privileged Role Administrator to elevate your account to the Cloud Application Administrator role for your tenant.




