Microsoft AD FS token-signing and encryption certificates are changed twice in quick succession if they are compromised, they are suspected of being compromised or they have not been changed in the past 12 months.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.