For the Universal GUI, we use Identity Provider "Azure" where IAM is linked based on Client ID and Client secret. Because "Client secrets" have an expiration date it is our preference to use a certificate instead of client secret ID, is this already possible?