Hi Everyone,
We are running into an issue configuring SAML authentication (using Azure Entra ID) for our Disaster Recovery (DR) environment.
Environment Details
Deployment Setup: Production and DR (Disaster Recovery) environments — both are exact replicas of each other.
ArcGIS Enterprise Version: 11.5
OS: Windows Server
Deployment Type: High Availability (HA)
Web Context URL: Identical on both Prod and DR
SSL Certificates: Identical on both Prod and DR
Use Case & Goal
To ensure members can seamlessly sign in after a failover event to our DR environment, we are configuring matching SAML certificates across both identical environments.
We followed the guidelines in the Esri documentation:
Reference: Organization-specific login considerations for geographic redundancy
Steps Completed So Far
Configured SAML Logins: Set up SAML authentication on both the Prod and DR environments using the same Federation Metadata URL.
Exported/Imported SAML Certificate: Exported the SAML certificate from Production and imported it into the DR environment.
Enabled Encrypted Assertions (Prod): Turned on Encrypted Assertions on the Production environment. ------> Working as expected.
Enabled Encrypted Assertions (DR): Turned on Encrypted Assertions on the DR environment. ------> Fails.
Issue & Error Details
When enabling Encrypted Assertions on the DR environment, authentication fails.

Has anyone encountered this behavior or can point out if we are missing any specific configuration steps for replica environments in Entra ID or ArcGIS Enterprise?
Thanks in advance for your assistance!
Regards,
Ayush