Create a custom authentication extension for account recovery claim validation
Learn how to set up a custom authentication extension that validates Verified ID claims during Microsoft Entra account recovery using an Azure Function and REST API.
Daily.Entra.NewsTrack documentation and Message Center changes for Microsoft Entra Verified ID.
Microsoft Learn documentation ↗Learn how to set up a custom authentication extension that validates Verified ID claims during Microsoft Entra account recovery using an Azure Function and REST API.
Learn how Verified ID in Microsoft Entra ID uses identity verification profiles to scope users to secure identity verification flows like account recovery.
| 1Kosmos | [1Kosmos offer](https://aka.ms/1kosmos) | [VerifiedIdentity](https://verifiedid.did.msidentity.com/v1.0/tenants/8108e610-606c-4dc3-ae95-d3ad8be3b24c/verifiableCredentials/contracts/1197e066-a9a2-2dc5-f245-4c31d1f4b456/manifest) | 1Kosmos and Microsoft Entra Verified ID unite to deliver trusted, privacy-preserving identity verification that empowers secure, passwordless access across ecosystems. |
Face Check is a premium feature within Verified ID. If you're a Microsoft Entra Suite customer, Face Check is included as part of the Suite. If you're not using Microsoft Entra Suite, you need to enable the Face Check Add-on in your Microsoft Entra Verified ID setup before doing Face Check verifications.
1. [Create a new user](../fundamentals/how-to-create-delete-users.md#create-a-new-user) to use in your testing.
Learn how to set up and use Face Check with Microsoft Entra Verified ID for high-assurance facial matching verifications that protect user privacy at enterprise scale.
- **Non-FIPS compliant signing keys (P-256K) retirement**: Non-FIPS compliant signing keys (P-256K) will be retired on July 1, 2026. If you haven't already, [upgrade your signing keys](signing-key-upgrade.md) to become FIPS compliant.
The portal verifies that `did.json` is reachable and correct when you select **Refresh registration status**. You should also consider verifying that you can request that URL in a browser to avoid errors like not using HTTPS, a bad TLS/SSL certificate, or the URL not being public. If the `did.json` file can't be requested anonymously in a browser or via tools such as `curl`, without warnings or errors, the portal won't be able to complete the **Refresh registration status** step.
- [Face Check with Microsoft Entra Verified ID pricing](~/verified-id/verified-id-pricing.md)
The issuer is an organization that creates an issuance solution requesting information from a user. The information is used to verify the user’s identity. For example, Woodgrove, Inc. has an issuance solution that enables them to create and distribute verifiable credentials (VCs) to all their employees. The employee uses the Authenticator app to sign in with their username and password, which passes an ID token to the issuing service. Once Woodgrove, Inc. validates the ID token submitted, the issuance solution creates a VC that includes claims about the employee and is signed with Woodgrove, Inc. DID. The employee now has an employer signed verifiable credential which includes the employee's DID as the subject DID.
Learn how to issue and verify credentials by using the Request Service REST API.
In this tutorial, you learn how to install the **Microsoft Authenticator** app and use it for the first time with Verified ID. You use the public end to end demo webapp to issue a verifiable credential to the **Authenticator** and present verifiable credentials from the **Authenticator**.
Microsoft’s Microsoft Entra Verified ID (Microsoft Entra VC) service enables you to trust proofs of user identity without expanding your trust boundary. With Microsoft Entra VC, you create accounts or federate with another identity provider. When a solution implements a verification exchange using verifiable credentials, it enables applications to request credentials that aren't bound to a specific domain. This approach makes it easier to request and verify credentials at scale.
Learn how to start a presentation request in Verifiable Credentials.
In this tutorial, you learn how to issue verifiable credentials, from directory based claims, by using a sample app.
In this tutorial, you learn how to use Face Check with Microsoft Entra Verified ID.
The Microsoft Entra Verified ID Admin API enables you to manage all aspects of the Verifiable Credential service. It offers a way to set up a brand new service, manage and create Verifiable Credential contracts, revoke Verifiable Credentials, and completely opt out of the service.
- [Set up a tenant for Microsoft Entra Verified ID](./verifiable-credentials-configure-tenant.md).
- **Free Microsoft Entra tenant** — [Create a new tenant](~/identity-platform/quickstart-create-new-tenant.md) with an [Azure free account](https://azure.microsoft.com/pricing/purchase-options/azure-account). This gives you Entra ID Free tier. You can then [activate a free trial of Microsoft Entra ID P1 or P2](~/fundamentals/get-started-premium.md) if needed for testing.
A design pattern describing how to onboard new employees remotely
A design pattern describing how to verify in helpdesk scenarios
Learn how to issue and verify by using the Request Service REST API.
In this article, you learn how to use a quickstart to create a custom verifiable credential for an ID token hint.
Learn how to use a quickstart to create custom credentials for ID tokens
Learn how to use a quickstart to create custom credentials for self-issued claims.
Learn how to use a quickstart to create custom credentials with multiple attestations.
Learn about Face Check with Microsoft Entra Verified ID billing model. Learn how to enable the Face Check add-on in your tenant by linking your Microsoft Azure subscription.
Learn how to use a quickstart to create custom credentials for from other Verifiable Credential attestation.
Learn how to link your domain to your decentralized identifier (DID).
Learn foundational information to plan and design your solution
A design pattern describing how to onboard new employees remotely
Learn to plan your end-to-end issuance solution.
Learn foundational information to plan and design your verification solution.
Learn how to revoke an issued verifiable credential.
In this tutorial, you learn how to manually configure your tenant to support the Verified ID service.
In this tutorial, you learn how to configure your tenant to verify credentials.
In this tutorial, you learn how to issue verifiable credentials, from directory based claims, by using a sample app.
In this tutorial, you learn how to issue verifiable credentials by using a sample app.
In this tutorial, you learn how to quickly configure your tenant to support the Verified ID service.
In this tutorial, you learn how to install and use Microsoft Authenticator for VerifiedID.
In this tutorial, you learn how to use Face Check with Microsoft Entra Verified ID.
Learn how to upgrade Microsoft Entra Verified ID signing keys to become FIPS compliant.
In this article, you learn how to use the Microsoft Entra Verified ID Network to verify credentials.
A design pattern describing how to verify in helpdesk scenarios
A design pattern describing how to verify in helpdesk scenarios
In this article, you learn how to use a quickstart to create a custom verifiable credential for an ID token hint.
In this tutorial, you learn how to configure your tenant to verify credentials.
The domain you verify ownership of to your DID is defined in the [overview section](verifiable-credentials-configure-tenant.md#set-up-verified-id). The domain needs to be a domain under your control and it should be in the format `https://www.contoso.com/`.
This article lists the latest features, improvements, and changes in the Microsoft Entra Verified ID service.
| Idemia | [Idemia documentation](https://na.idemia.com/identity/verifiable-credentials/) | Idemia Integration with Microsoft Entra Verified ID enables "Verify once, use everywhere" functionality. |
A Microsoft Entra documentation page was updated: Linkedin Employment Verification.
The Microsoft Entra Verified ID Admin API enables you to manage all aspects of the Verifiable Credential service. It offers a way to set up a brand new service, manage and create Verifiable Credential contracts, revoke Verifiable Credentials and completely opt out the service as well.
The following four attestation types are currently available to be configured in the rules definition. They are different ways of providing claims used by the Microsoft Entra Verified ID issuing service to be inserted into a verifiable credential and attest to that information with your decentralized identifier (DID). Multiple attestation types can be used in the rules definition.
In order to be able to resolve DID documents, DIDs are typically recorded on an underlying network of some kind that represents a trust system. Microsoft currently supports DID:Web trust system. DID:Web is a permission based model that allows trust using a web domain’s existing reputation. DID:Web is in support status General Available.
The domain you verify ownership of to your DID is defined in the [overview section](verifiable-credentials-configure-tenant.md#set-up-verified-id). The domain needs to be a domain under your control and it should be in the format `https://www.example.com/`.
1. On the start page of **Microsoft Entra Verified ID** in the **Azure portal**, you have a quickstart named **Verification request**. Selecting **start** takes you to a page where you can browse the Verifiable Credentials Network.
To configure IDEMIA as your identity verification proofing solution, follow these steps:
In centralized identity systems, the identity provider (IDP) controls the lifecycle and usage of credentials.
To receive a verifiable credential, your users need to sign into your IDP from the **Microsoft Authenticator** app.
> If the verifiable credential is old and was issued during the preview period, this claim doesn't exist. Revocation doesn't work for this credential and you have to reissue it.
All verifiable credentials must declare their *type* in their [rules definition](rules-and-display-definitions-model.md#rulesmodel-type). The credential type distinguishes a verifiable credentials schema from other credentials and it ensures interoperability between issuers and verifiers. To indicate a credential type, provide one or more credential types that the credential satisfies. Each type is a unique string. Often, a URI is used to ensure global uniqueness. The URI doesn't need to be addressable. It's treated as a string. As an example, a diploma credential issued by Contoso University might declare the following types:
:::image type="content" source="media/plan-verification-solution/plan-verification-solution-authenticator.png" alt-text="Diagram of the components of a verification solution with Microsoft Authenticator application highlighted.":::
| `type` | string (array) | a list of verifiable credential types this contract can issue |
You could select a partner from the list and build seamless end-user experiences for onboarding, secure access to critical services, self-service, and custom business application scenarios. If you're a Services or solution Partner and would like to be considered into Microsoft Entra Verified ID partner documentation, submit your application [request](https://forms.microsoft.com/r/AGVsXmf4EZ).
In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.
In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.
In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.
In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.
Face Check is a privacy-respecting facial matching. It allows enterprises to perform high-assurance verifications securely, simply, and at scale. Face Check adds a critical layer of trust by performing facial matching between a user’s real-time selfie and a photo. The facial matching is powered by Azure AI services. Face Check protects user privacy by sharing only the match results and not any sensitive identity data, while allowing organizations to be sure the person claiming an identity is really them.
In this tutorial, you learn how to install the **Microsoft Authenticator** app and use it for the first time with Verified ID. You use the public end to end demo webapp to issue a verifiable credential to the **Authenticator** and present verifiable credentials from the **Authenticator**.
- **[Android Studio](https://developer.android.com/studio)** installed on Mac/Windows and an Android test device. You need to enable [developer mode](https://developer.android.com/studio/debug/dev-options) on your Android test device.