External IDP
When you install XProtect a single-server environment, Identity Provider configuration data is protected using the Data Protection API (DPAPI).
In a failover cluster, this data is not shared, so you must ensure that the configuration is identical on all nodes.
Import the server certificate to the Personal store for the user running the Management Server service.
Grant the server certificate Read permissions.
Ensure the root certificate that you used to create the server certificate is imported to the User certificates > Trusted Root Certification Authorities store.
If using a self-signed certificate, add it to the Trusted Root Certificates Authorities store on your local computer.
Retrieve the certificate thumbprint (see How to retrieve a certificate thumbprint)
Edit
appsettings.jsonunder the Identity Provider install path Identity Provider ([Install path]\Milestone\XProtect Management Server\IIS\IDP).Add the certificate thumbprint under
DataProtectionSettings:"DataProtectionSettings": { "ProtectKeysWithCertificate": { "Thumbprint": "[thumbprint]" } },Repeat on the remaining Management Server nodes.