@mark-robustelli Well, here are some screenshots:

at first I added a new IdP - via API POST /api/identity-provider - and the existing dummy/placeholder certificate is linked:
7ee96348-07c1-4845-8a9a-26998572d0e0-image.png
-> this is the only IdP

then I import - via API POST /api/key/import - the correct certificate:
ab51c6c5-1c2b-4939-a01d-2e045274400d-image.png

but I do not link this in the IdP, and so do not set the Verification key

Do I get it right, that the login should not work in that case? But I am able to login via this EntraID IdP.