Hello Scott Lee,
If the federation metadata endpoint is no longer reachable over HTTPS/443, AD FS cannot automatically refresh the relying party trust metadata. In that situation, obtain the latest federation metadata XML file directly from the partner application owner and copy it locally to the AD FS server. Microsoft's supported method is to manually update the trust by running Update-AdfsRelyingPartyTrust -TargetName "<RelyingPartyTrustName>" -MetadataFile "C:\Temp\federationmetadata.xml", which refreshes endpoints, claim settings, and signing certificates from the supplied metadata file.
If the metadata file cannot be obtained, manually verify and update the relying party's signing certificates, endpoints, and identifiers in AD FS Management > Trust Relationships > Relying Party Trusts > Properties, ensuring any expired signing certificates are removed and replaced with the current ones. Certificate trust and validity must also be verified, as AD FS authentication will fail if token-signing certificates are expired, untrusted, or incorrectly configured.
If my answer is useful for you, please hit Accept the answer for me please.
HL.