Which occurrence of the < X509Certificate > XML element are you using? I am using the first one as mentioned in this KB article and it works fine for me for years. However, it is just testing certificate I have. If Azure is rotating the certs, then this is not really a Kentico thing. You can create e.g. some scheduled task which will be rotating the settings value too. Or, you can use fully custom external authentication and ensure entire logic on your own. And, I have found also this article which might be helpful.