← Previous day

Next day →
Plain-English daily brief

What changed on this day

58 changes were tracked across 5 Microsoft Entra products. The leading updates include Mandatory Multifactor Authentication; AD FS application migration to move AD FS apps to Microsoft Entra ID; Application consent management and evaluation of consent requests.

58 updates

General

5

Mysdworxcom Tutorial

Updated

You can configure and test Microsoft Entra single sign-on for my.sdworx.com in a test environment (my.acc.sdworx.com) but not by using the gallery app (import SP metadata, to be provided by your my.sdworx.com contact). My.sdworx.com supports **IDP** and **SP** initiated single sign-on.

Authentication

3

Fundamentals

2

Fido2 Hardware Vendor

Updated

ACS FIDO Authenticator NFC|c89e6a38-6c00-5426-5aa5-c9cbf48f0382|❌|✅|✅|❌

Security

2

Standards

2

AD FS application migration to move AD FS apps to Microsoft Entra ID

Updated

Learn how to use the AD FS application migration to migrate AD FS relying party applications from ADFS to Microsoft Entra ID. This guided experience provides one-click configuration for basic SAML URLs, claims mapping, and user assignments to integrate the application with Microsoft Entra ID.

Governance

1

Integrate Darwinbox HR with Microsoft Entra ID

Updated

The document provides a step-by-step guide for integrating Darwinbox with Microsoft Entra ID. The steps include establishing a connection, configuring attribute mapping, testing account provisioning, configuring account access rules, and monitoring provisioning. Use this integration to configure cloud-native users directly in Microsoft Entra ID. This integration allows IT admins to automate business processes using Microsoft Entra ID Governance Lifecycle Workflows.

Provisioning

1

Fundamentals

1

21790

Updated

- [Cross-tenant access overview](../../external-id/cross-tenant-access-overview.md)

Security

17

Use Quickstart Idtoken

Updated

In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.

Issuer Revoke

Updated

> If the verifiable credential is old and was issued during the preview period, this claim doesn't exist. Revocation doesn't work for this credential and you have to reissue it.

Use Quickstart

Updated

In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.

Use Quickstart Presentation

Updated

In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.

Use Quickstart Selfissued

Updated

In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.

Using Facecheck

Updated

Face Check is a privacy-respecting facial matching. It allows enterprises to perform high-assurance verifications securely, simply, and at scale. Face Check adds a critical layer of trust by performing facial matching between a user’s real-time selfie and a photo. The facial matching is powered by Azure AI services. Face Check protects user privacy by sharing only the match results and not any sensitive identity data, while allowing organizations to be sure the person claiming an identity is really them.

Admin Api

Updated

The Microsoft Entra Verified ID Admin API enables you to manage all aspects of the Verifiable Credential service. It offers a way to set up a brand new service, manage and create Verifiable Credential contracts, revoke Verifiable Credentials and completely opt out the service as well.

Verifiable Credentials Faq

Updated

1. In the [Azure portal](https://portal.azure.com), go to **Microsoft Entra ID** for the subscription you use for your Microsoft Entra Verified ID deployment.

Credential Design

Updated

The following four attestation types are currently available to be configured in the rules definition. They are different ways of providing claims used by the Microsoft Entra Verified ID issuing service to be inserted into a verifiable credential and attest to that information with your decentralized identifier (DID). Multiple attestation types can be used in the rules definition.

Verifiable Credentials Configure Issuer

Updated

In this step, you create the verified credential expert card by using Microsoft Entra Verified ID. After you create the credential, your Microsoft Entra tenant can issue it to users who initiate the process.

How Use Vcnetwork

Updated

1. On the start page of **Microsoft Entra Verified ID** in the **Azure portal**, you have a quickstart named **Verification request**. Selecting **start** takes you to a page where you can browse the Verifiable Credentials Network.

Opt Out

Updated

1. From the **Azure portal**, search for verifiable credentials.

Plan Issuance Solution

Updated

All verifiable credentials must declare their *type* in their [rules definition](rules-and-display-definitions-model.md#rulesmodel-type). The credential type distinguishes a verifiable credentials schema from other credentials and it ensures interoperability between issuers and verifiers. To indicate a credential type, provide one or more credential types that the credential satisfies. Each type is a unique string. Often, a URI is used to ensure global uniqueness. The URI doesn't need to be addressable. It's treated as a string. As an example, a diploma credential issued by Contoso University might declare the following types:

Verifiable Credentials Configure Verifier

Updated

Create a client secret for the registered application you created. The sample application uses the client secret to prove its identity when it requests tokens.

Developer

6

Services Partners

Updated

You could select a partner from the list and build seamless end-user experiences for onboarding, secure access to critical services, self-service, and custom business application scenarios. If you're a Services or solution Partner and would like to be considered into Microsoft Entra Verified ID partner documentation, submit your application [request](https://forms.microsoft.com/r/AGVsXmf4EZ).

Whats New

Updated

Applications that use the Microsoft Entra Verified ID service must use the Request API endpoint that corresponds to their Microsoft Entra tenant's region.

General

5

Idemia

Updated

To configure IDEMIA as your identity verification proofing solution, follow these steps:

Verified Id Pricing

Updated

To take advantage of the consumptive billing, your Verified ID authority must be linked to an Azure subscription.

Authentication

2

Using the Microsoft Authenticator with Verified ID

Updated

In this tutorial, you learn how to install the **Microsoft Authenticator** app and use it for the first time with Verified ID. You use the public end to end demo webapp to issue a verifiable credential to the **Authenticator** and present verifiable credentials from the **Authenticator**.

Plan Verification Solution

Updated

:::image type="content" source="media/plan-verification-solution/plan-verification-solution-authenticator.png" alt-text="Diagram of the components of a verification solution with Microsoft Authenticator application highlighted.":::

Fundamentals

2

Decentralized Identifier Overview

Updated

In order to be able to resolve DID documents, DIDs are typically recorded on an underlying network of some kind that represents a trust system. Microsoft currently supports DID:Web trust system. DID:Web is a permission based model that allows trust using a web domain’s existing reputation. DID:Web is in support status General Available.

Dnsbind

Updated

The domain you verify ownership of to your DID is defined in the [overview section](verifiable-credentials-configure-tenant.md#set-up-verified-id). The domain needs to be a domain under your control and it should be in the format `https://www.example.com/`.

Standards

2

Issuer Openid

Updated

To receive a verifiable credential, your users need to sign into your IDP from the **Microsoft Authenticator** app.

Architecture

1

Microsoft identity platform

1

Using Wallet Library

Updated

- **[Android Studio](https://developer.android.com/studio)** installed on Mac/Windows and an Android test device. You need to enable [developer mode](https://developer.android.com/studio/debug/dev-options) on your Android test device.

Troubleshooting

1

Error Codes

Updated

"message": "The request contains `includeQRCode`, but it is not boolean."

Fundamentals

1

Overview

Updated

- A service principal of a special type is created in Microsoft Entra ID for the identity. The service principal is tied to the lifecycle of that Azure resource. When the Azure resource is deleted, Azure automatically deletes the service principal for you.

General

2

Install Windows Client

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.

Configure Global Access With Pim

Updated

Next, we activate group membership using the Microsoft Entra admin center, and then attempt to connect with the new role activated.

Troubleshooting

1