The private key is known only to you and is what is used in conjunction with the CSR to generate the certificate. You can check what is provided to you by the Certificate Authority, used to generate the certificate. Or simply cancel the certificate and re-issue it through the provider keeping hold of the private key (coping the private key) when you go through the new certificate generation process within the certificate authorities portal.
Specifically about the Certificates that you asked about, as mentioned in Step 2, the certificate you generate can't be from any CA, it needs to be from one that is in the MS approved list that we link to.