Azure and SAML certificate expiration monitoring

Using the new Azure V2 integration in checkmk 2.5 and it still looks like it is unable to monitor for expiring secrets/certificates for Enterprise Applications in Azure, in my specific case it is for SAML certificates.

I see there is an extension available on the Exchange but it would be very nice if this was a native feature as it seems like a fairly large monitoring gap to have in the official integration.

See also Application and service principal objects in Microsoft Entra ID.

This should work, today i connected an Azure v2 special agent to an Azure environment and got instantly many expired certs and secrets.

Yes it works perfectly fine for app registrations but not for Enterprise Applications. In MS own words app registrations are like templates for Enterprise Applications. Obviously many people just use them directly but in the eyes of MS you should then use the template app registration to create an enterprise application for specific configurations.

For example I have both an app registration and an enterprise app using that app registration where the SAML certificate is configured on the enterprise application. As far as Checkmk is concerned nothing is wrong, it doesn’t even discover the app registration for ‘Cisco Intersight’ (which I know is working because it does discover other app registrations with secrets and certificates).


Here app registration shows 0 certificates and 0 secrets.