Share via

Reduce expiry dates for existing Client Secrets for App Registrations & Service Principals?

Michael Herold 0 Reputation points
2026-06-19T09:25:26.82+00:00

Hello!

In the past, our organization has generated client secrets for SPNs with a secret expiry date of 10 years in the future. With a policy update, this is no longer allowed. Instead of forcing a large number of customers to replace their secrets right now, is there a way to reduce the expiry date of the existing secrets to conform to the new limit?

On a related note, when you generate a new client secret for a Service Principal which already has exsting (non-expired) secrets, are those other secrets in any way invalidated or their validity shortened? There's a rumor that those get set to 7 days grace period regardless of their previous expiry date, but I couldn't find any mention of this in any of the official Azure documentation.

Thank you!

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. Vasil Michev 127K Reputation points MVP Volunteer Moderator
    2026-06-19T09:29:36.41+00:00

    Afaik there is no way to reduce the validity period for existing secrets. But creating new ones will not impact them in any way, they continue to be valid until the expiration day. Not sure where you saw that 7-day grace period, but it's news to me.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.