Skip to content
arrow_back
search
ISM-1956 policy ASD Information Security Manual (ISM)

Regularly Update AD FS Certificates to Prevent Risks

AD FS certificates must be updated twice quickly if compromised or not updated within a year to enhance security.

record_voice_over

Plain language

It's crucial to regularly update your Active Directory Federation Services (AD FS) certificates. If these certificates are outdated or compromised, hackers could gain access to your systems, leading to data breaches and unauthorised access to sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Microsoft AD FS token-signing and encryption certificates are changed twice in quick succession if they are compromised, they are suspected of being compromised or they have not been changed in the past 12 months.
policy ASD Information Security Manual (ISM) ISM-1956
priority_high

Why it matters

Delayed AD FS certificate updates increase risk of token forgery and unauthorised access if token-signing or encryption certificates are compromised or stale.

settings

Operational notes

Rotate AD FS token-signing and encryption certificates at least every 12 months. If compromise is suspected, perform two rapid successive certificate changes and update relying parties.

Mapping detail

Mapping

Direction

Controls