The Primary AD FS Token Decrypting certificate does not have a private key. AD FS cannot decrypt tokens from trusted claims ...