Select the PKCS#12 certificate used to authenticate with the service principal.
You can add a Certificate to the Jenkins Credentials store and it will show up in the list.
Note: The certificate will be used only when the Client Secret is not provided.