# How to update Zivver SAML metadata and verify in ADFS

## Introduction

Your organization is using Single Sign-On to log users in to Zivver via ADFS. Your Identity Provider (IdP) and Zivver (Service Provider (SP)) exchange metadata. This metadata contains necessary information so that the IdP and Zivver can trust each other. The metadata is signed with a certificate.

Two different methods exist for updating the Zivver metadata in ADFS.

1. [How to update the Zivver metadata in ADFS via URL - Recommended](https://docs.zivver.com/en/admin/sso/update-zivver-saml-metadata-adfs.html#url)
2. [How to update the Zivver metadata in ADFS via XML import](https://docs.zivver.com/en/admin/sso/update-zivver-saml-metadata-adfs.html#import)

## How to update the Zivver metadata in ADFS via URL - Recommended

Updating the Zivver metadata in ADFS via URL can be done in three ways. Choose the method that suits your preference.

1. [Automatically - Recommended](https://docs.zivver.com/en/admin/sso/update-zivver-saml-metadata-adfs.html#automatically---recommended)
2. [PowerShell](https://docs.zivver.com/en/admin/sso/update-zivver-saml-metadata-adfs.html#powershell)
3. [Manually (via user interface)](https://docs.zivver.com/en/admin/sso/update-zivver-saml-metadata-adfs.html#manually-via-user-interface)

### Automatically - Recommended

When the monitoring features are enabled, ADFS monitors for new metadata every 24 hours (1440 minutes) by default. You can see how often ADFS checks for new metadata by running the PowerShell command:

```powershell
Get-ADFSProperties | select MonitoringInterval
```

Do these steps to set up automatic monitoring for Zivver metadata.

1. Open ADFS Management Console
2. Open **Trust Relationships** > **Relying Party Trusts**
3. Right-click the Zivver relying party trust and select **Properties**

4. Open the tab **Monitoring**
5. At **Relying party’s federation metadata URL** enter the URL `https://app.zivver.com/api/sso/saml/meta`
6. Click **Test URL**

If you see the error message

> An error occurred during an attempt to read the federation metadata. Verify that the specified URL or host name is a valid federation metadata endpoint. Do a check on your proxy server setting. For more information […]

add this registry key to the AD FS server. Then, reboot the server.

**Location**: `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319`

**DWORD name**: `SchUseStrongCrypto`

**Value**: `1`

7. Select **Monitor relying party**
8. Also select **Automatically update relying party**

9. Click **Apply**.

The metadata should be updated after 24 hours. [Verify the metadata is updated](https://docs.zivver.com/en/admin/sso/update-zivver-saml-metadata-adfs.html#how-do-i-verify-the-metadata-is-updated).

### PowerShell

1. Start a PowerShell command line with **elevated rights**
2. Run command:

```powershell
Update-AdfsRelyingPartyTrust -TargetIdentifier "https://app.zivver.com/SAML/Zivver"
```

The metadata should be updated. [Verify the metadata is updated](https://docs.zivver.com/en/admin/sso/update-zivver-saml-metadata-adfs.html#how-do-i-verify-the-metadata-is-updated).

### Manually (via user interface)

1. Open ADFS Management Console
2. Open **Trust Relationships** > **Relying Party Trusts**
3. Right-click the Zivver relying party trust and select **Update from Federation Metadata…**

4. Click **Update**

The metadata is now updated. [Verify the metadata is updated](https://docs.zivver.com/en/admin/sso/update-zivver-saml-metadata-adfs.html#how-do-i-verify-the-metadata-is-updated).

## How to update the Zivver metadata in ADFS via XML import

If updating the Zivver metadata via URL is not an option, you can download the new Zivver metadata and import it into ADFS via PowerShell.

1. Open a modern browser like Google Chrome
2. Go to [https://app.zivver.com/api/sso/saml/meta](https://app.zivver.com/api/sso/saml/meta)
3. Download the metadata as an `.xml` file via `Ctrl + S` or, when using Chrome, via the hamburger menu in the top right corner > **More Tools** > **Save page as…**

_Make sure the file is saved with `.xml` as the file extension. The file name is often `meta.xml`._
4. Transfer the `meta.xml` file to the ADFS server
5. Start a **PowerShell ISE** instance with **elevated rights**
6. Run this script:

_Make sure the `meta.xml` file is stored directly on the C-drive._

```powershell
$metadataPath = "c:\meta.xml"
$zivverIdentifier = "https://app.zivver.com/SAML/Zivver"
Update-AdfsRelyingPartyTrust -TargetIdentifier $zivverIdentifier -MetadataFile $metadataPath
```

## How do I verify the metadata is updated?

4. Open the **Encryption** tab
5. Verify that the **Expiration date** is **11/15/2026** or **15/11/2026**, depending on your date and time settings.

Updated on 2026-07-03
