Does Microsoft Entra (Entra ID / Azure AD) automatically notify app owners when client secrets are about to expire?

Bhatt, Dhaval [ITSUS] 0 Reputation points
2026-10-05T18:31:30.68+00:00

I’m checking how Entra handles client secret expirations and want to confirm expected behavior and built‑in options.

What I see today:

  • The Entra admin center shows the Recommendation "Renew expiring application credential" and each App registration’s Certificates & secrets blade shows client secret expiry dates.
  • I can’t find a tenant‑level automatic feature that sends email/Teams alerts to app owners when a client secret is approaching expiration.

Questions:

  1. Is there an out‑of‑the‑box way in Microsoft Entra/Entra ID to automatically notify application owners (or configured recipients) when a client secret will expire in X days? If so, how do I enable or configure it?
  2. Are there any tenant settings, preview features, or built‑in alerting tied to Recommendations that will send per‑owner notifications for expiring client secrets?
  3. If native alerts are not available, what Microsoft‑recommended patterns exist for monitoring client secret expiry (examples, sample scripts, or docs would be appreciated)?
  4. Any known roadmap items or upcoming features that will add automatic client‑secret expiry notifications?
Microsoft Security | Microsoft Entra | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-10-05T18:31:50.56+00:00

    For Microsoft Entra app registrations, there is no documented out-of-the-box feature in the provided material that automatically emails application owners when a client secret is nearing expiration.

    Supported built-in options shown in the material are:

    1. Manual monitoring in the app registration
      • Go to Microsoft Entra admin center → App registrations → select the app → Certificates & secrets.
      • Check the Expires column for each client secret.
    2. Microsoft Entra recommendations
      • Microsoft Entra includes the recommendation Renew expiring application credentials.
      • The recommendations overview shows this recommendation targets Application Administrator for email notifications.
      • The Microsoft.Identity.Web guidance also states that Microsoft Entra recommendations can be set up to receive alerts before credentials expire.
    3. Rotation planning
      • Client secrets have a maximum lifetime and expire on the date specified during creation.
      • Microsoft recommends planning rotation to avoid outages.
      • For apps using Microsoft.Identity.Web, a zero-downtime pattern is to add a new secret first in the ClientCredentials array, deploy, validate, and then remove the old secret.
    4. Monitoring and automation patterns
      • The security operations guidance recommends monitoring applications for long credential expiration times and using Microsoft Graph to find credential start and end dates.
      • It also points to prebuilt monitoring and alerting options such as Microsoft Sentinel, Azure Monitor, Defender for Cloud Apps, and a sample PowerShell script to find credential lifetime.
      • The certificates FAQ states that app registrations with expiring secrets and certificates can be exported through PowerShell scripts.

    What can be answered directly for each question:

    1. Automatic per-owner notifications for expiring client secrets
      • No documented per-owner automatic email or Teams notification feature for client secrets is shown.
      • The documented native capabilities are the Certificates & secrets expiry view and Microsoft Entra recommendations.
    2. Tenant settings, preview features, or recommendation-based alerts
      • The recommendation Renew expiring application credentials exists and is listed as Preview.
      • The recommendations table indicates Application Administrator as the target role for email notifications.
      • No tenant setting is shown that sends notifications specifically to each application owner, and no Teams alert capability is documented in the provided material.
    3. Microsoft-recommended monitoring patterns if native alerts are insufficient
      • Use Certificates & secrets to track expiration dates.
      • Use Microsoft Entra recommendations for alerting on expiring application credentials.
      • Use Microsoft Graph or the referenced PowerShell scripts to inventory credentials and expiration dates.
      • Use monitoring/alerting integrations called out in the security operations guidance: Microsoft Sentinel, Azure Monitor, Defender for Cloud Apps, and PowerShell-based reporting.
      • Rotate secrets before expiry; for Microsoft.Identity.Web apps, use the documented dual-secret approach for zero downtime.
    4. Roadmap or upcoming features
      • No roadmap or upcoming feature for automatic client-secret expiry notifications is described in the provided material.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.