Invalid thumbprint -Pingfed and Microsoft Defender for Cloud Apps

Hi All,
we are facing the below error in our implementation.
error=access_denied&error_description=Invalid%20thumbprint%20

Auth0 has been configured as a Service Provider (SP) in a federated SAML arrangement, where Pingfed is the IDP.
Auth0 would send the request to MCAS (Microsoft Defender for Cloud Apps), which would then pass it on to Pingfed.
The client has asked us to configure the MCAS URL as SAML sign-in URL and gave the signing certificate of Pingfed. Do you think we need to check about this certificate? What certificate do we have to use in the architecture where Auth0 would send the request to MCAS (Microsoft Defender for Cloud Apps), which would then pass it on to Pingfed?