Azure App Service ist ein Dienst, der zur Erstellung und Bereitstellung von skalierbaren, unternehmenskritischen Web-Apps verwendet wird.
App Service Certificate Denied – Refund or Credit for Unused Purchased Period?
We have an existing Azure App Service Certificate for a wildcard domain, for example:
*.example.com
The certificate itself expired on July 28, 2026, and the certificate order is now in Denied status because the required domain ownership verification was not completed within the 15-day verification period.
We have since corrected the Key Vault configuration and successfully connected the App Service Certificate to a new dedicated Key Vault. The Key Vault setup is now working correctly.
However, the existing certificate order appears to be unrecoverable:
- Rekey fails with the following message:
Certificates with fewer than 30 days remaining in the current purchase period cannot be reissued.Renewal / Auto Renew is unavailable because the certificate status isDenied. The Azure portal states that a certificate cannot be renewed when it is denied, revoked, expired, or cancelled.
Because of this, it appears that the only remaining option is to create a completely new Azure App Service Certificate resource.
The issue is that the existing App Service Certificate resource still shows a purchased period until July 29, 2027, even though the currently issued certificate expired on July 28, 2026 and the renewal/issuance attempt was denied.
Creating a new Wildcard App Service Certificate currently costs $299.99/year, and the Azure portal clearly states that creating the new resource authorizes a new charge.
My questions are therefore:
If we create a new Wildcard App Service Certificate for the same domain, will we be charged the full $299.99again even though the existing certificate resource shows a purchased period running until July 29, 2027?
If a new purchase is required, is it possible to receive a refund, credit, or adjustment for the unused period of the existing certificate resource?
Is there any supported way to recover or replace the denied certificate within the already purchased period without purchasing another App Service Certificate?
We would like to avoid paying twice for essentially the same certificate period and would appreciate clarification on the correct procedure.We have an existing Azure App Service Certificate for a wildcard domain, for example:
*.example.com
The certificate itself expired on July 28, 2026, and the certificate order is now in Denied status because the required domain ownership verification was not completed within the 15-day verification period.
We have since corrected the Key Vault configuration and successfully connected the App Service Certificate to a new dedicated Key Vault. The Key Vault setup is now working correctly.
However, the existing certificate order appears to be unrecoverable:
Rekey fails with the following message:
Certificates with fewer than 30 days remaining in the current purchase period cannot be reissued.
Renewal / Auto Renew is unavailable because the certificate status is Denied.
The Azure portal states that a certificate cannot be renewed when it is denied, revoked, expired, or cancelled.
Because of this, it appears that the only remaining option is to create a completely new Azure App Service Certificate resource.
The issue is that the existing App Service Certificate resource still shows a purchased period until July 29, 2027, even though the currently issued certificate expired on July 28, 2026 and the renewal/issuance attempt was denied.
Creating a new Wildcard App Service Certificate currently costs $299.99/year, and the Azure portal clearly states that creating the new resource authorizes a new charge.
My questions are therefore:
If we create a new Wildcard App Service Certificate for the same domain, will we be charged the full $299.99again even though the existing certificate resource shows a purchased period running until July 29, 2027?
If a new purchase is required, is it possible to receive a refund, credit, or adjustment for the unused period of the existing certificate resource?
Is there any supported way to recover or replace the denied certificate within the already purchased period without purchasing another App Service Certificate?
We would like to avoid paying twice for essentially the same certificate period and would appreciate clarification on the correct procedure.