---
title: Create a Self-Signed Certificate for EXO Authentication
slug: create-a-self-signed-certificate-for-exo-authentication
docTags: 
createdAt: 2026-01-29T20:45:55.932Z
---

This document details the steps to create a self-signed certificate with the intended use to authenticate with Exchange Online.

1. Logon to Activate Server
2. Run PowerShell as Administrator
3. Copy the script below to the server, modify the cert name, password and export path as required.

```powershell
$certName = "Azure EXO Cert"
$certPath = "Cert:\LocalMachine\My"
$exportPath = "C:\Temp"

# Create export folder if it doesn't exist
if (!(Test-Path -Path $exportPath)) {
    New-Item -Path $exportPath -ItemType Directory | Out-Null
}

# Create the self-signed certificate
$cert = New-SelfSignedCertificate `
    -Subject "CN=$certName" `
    -KeyAlgorithm RSA `
    -KeyLength 2048 `
    -KeyExportPolicy Exportable `
    -KeySpec Signature `
    -CertStoreLocation $certPath `
    -NotAfter (Get-Date).AddYears(2) `
    -HashAlgorithm SHA256 `
    -FriendlyName $certName

# Export the public certificate (.cer) for Azure AD
Export-Certificate `
    -Cert $cert `
    -FilePath "$exportPath\$certName.cer" `
    -Force

# Define and secure the password for the private key
$plainPassword = "<ENTER PASSWORD>"
$securePassword = ConvertTo-SecureString -String $plainPassword -Force -AsPlainText

# Export the private certificate (.pfx) with the secure password
Export-PfxCertificate `
    -Cert $cert `
    -FilePath "$exportPath\$certName.pfx" `
    -Password $securePassword `
    -Force
```

4. Run PowerShell as Administrator and run the above script.
5. Browse to the export folder
6. Double click the certificate PFX file to install it.
7. Set Store Location to Local Machine, click Next
8. Click Yes to UAC to run as Administrator in Windows
9. Click Next
10. Enter the password that was used to generate the certificate
11. Click Next
12. Place all certificates in the following store: Personal, click Next
13. Finish
