Associate a certificate with the Entra app ID for BEMS
- Complete one of the following tasks:
Certificate
Task
If you are using an existing CA server
- Request the certificate. The certificate that you request must include the app name in the subject of the certificate. The <appname> is the name you assigned the app in step 5 of Obtain an Entra app ID for BEMS with certificate-based authentication.
- Export the public key of the certificate as a .cer or .pem file. The public key is used for the Entra app ID that is created.
- Export the private key of the certificate as a .pfx file. The private key is imported to the BEMS dashboard.
If you are using a self-signed certificate
- Create a self-signed certificate using the New-SelfSignedCertificate command. For more information, visit the Microsoft resource New-SelfSignedCertificate.
- On the computer running Microsoft Windows, open the Windows PowerShell.
- Run the following command: $cert=New-SelfSignedCertificate -Subject "CN=<appname>" -CertStoreLocation "Cert:\CurrentUser\My" -KeyExportPolicy Exportable -KeySpec Signature.
Where <appname> is the name that you assigned the app in step 5 of Obtain an Entra app ID for BEMS with certificate-based authentication. The certificate that you request must include the Entra appname in the subject field.
- Export the public key from the Microsoft Management Console (MMC). Save the public certificate as a .cer or .pem file. The public key is used for the Entra app ID that is created.
- On the computer running Windows, open the Certificate Manager for the logged in user.
- Expand Personal.
- Click Certificates.
- Right-click the <user>@<domain> and click All Tasks > Export.
- In the Certificate Export Wizard, click No, do not export private key.
- Click Next.
- Select Base-64 encoded X.509 (.cer). Click Next.
- Provide a name for the certificate and save it to your desktop.
- Click Next.
- Click Finish.
- Click OK.
- Export the private key from the Microsoft Management Console (MMC). Make sure to include the private key and save it as a .pfx file. For instructions, see the Microsoft resource Export a Certificate with the Private Key. The private key is imported to the BEMS dashboard.
- On the computer running Windows, open the Certificate Manager for the logged in user.
- Expand Personal.
- Click Certificates.
- Right-click the <user>@<domain> and click All Tasks > Export.
- In the Certificate Export Wizard, click Yes, export private key..
- Click Next.
- Select Personal Information Exchange – PKCS #12 (.pfx). Click Next.
- Select the security method.
- Provide a name for the certificate and save it to your desktop.
- Click Next.
- Click Finish.
- Click OK.
- Upload the public certificate (.pem or .cer file) that you exported in step 1 to associate the certificate credentials with the Entra app ID for BEMS.
- In entra.microsoft.com, open the <app name> you assigned the app in step 5 of Obtain an Entra app ID for BEMS with certificate-based authentication.
- Click Certificates & secrets.
- In the Certificates section, click Upload certificate.
- In the Select a file search field, navigate to the location where you exported the certificate in step 1.
- Click Add.