Product

Microsoft Entra Verified ID

Track documentation and Message Center changes for Microsoft Entra Verified ID.

Microsoft Learn documentation ↗

Latest Microsoft Entra Verified ID changes

Whats New

General

A Microsoft Entra documentation page was updated: Whats New.

Idv Partners

Authentication

| 1Kosmos | [1Kosmos offer](https://aka.ms/1kosmos) | [VerifiedIdentity](https://verifiedid.did.msidentity.com/v1.0/tenants/8108e610-606c-4dc3-ae95-d3ad8be3b24c/verifiableCredentials/contracts/1197e066-a9a2-2dc5-f245-4c31d1f4b456/manifest) | 1Kosmos and Microsoft Entra Verified ID unite to deliver trusted, privacy-preserving identity verification that empowers secure, passwordless access across ecosystems. |

Using Facecheck

General

Face Check is a premium feature within Verified ID. If you're a Microsoft Entra Suite customer, Face Check is included as part of the Suite. If you're not using Microsoft Entra Suite, you need to enable the Face Check Add-on in your Microsoft Entra Verified ID setup before doing Face Check verifications.

Use Quickstart Verifiedemployee

Fundamentals

1. [Create a new user](../fundamentals/how-to-create-delete-users.md#create-a-new-user) to use in your testing.

Whats New

General

- **Non-FIPS compliant signing keys (P-256K) retirement**: Non-FIPS compliant signing keys (P-256K) will be retired on July 1, 2026. If you haven't already, [upgrade your signing keys](signing-key-upgrade.md) to become FIPS compliant.

Register Didwebsite

Troubleshooting

The portal verifies that `did.json` is reachable and correct when you select **Refresh registration status**. You should also consider verifying that you can request that URL in a browser to avoid errors like not using HTTPS, a bad TLS/SSL certificate, or the URL not being public. If the `did.json` file can't be requested anonymously in a browser or via tools such as `curl`, without warnings or errors, the portal won't be able to complete the **Refresh registration status** step.

Decentralized Identifier Overview

Fundamentals

The issuer is an organization that creates an issuance solution requesting information from a user. The information is used to verify the user’s identity. For example, Woodgrove, Inc. has an issuance solution that enables them to create and distribute verifiable credentials (VCs) to all their employees. The employee uses the Authenticator app to sign in with their username and password, which passes an ID token to the issuing service. Once Woodgrove, Inc. validates the ID token submitted, the issuance solution creates a VC that includes claims about the employee and is signed with Woodgrove, Inc. DID. The employee now has an employer signed verifiable credential which includes the employee's DID as the subject DID.

Plan Verification Solution

Security

Microsoft’s Microsoft Entra Verified ID (Microsoft Entra VC) service enables you to trust proofs of user identity without expanding your trust boundary. With Microsoft Entra VC, you create accounts or federate with another identity provider. When a solution implements a verification exchange using verifiable credentials, it enables applications to request credentials that aren't bound to a specific domain. This approach makes it easier to request and verify credentials at scale.

Verifiable credentials admin API

Security

The Microsoft Entra Verified ID Admin API enables you to manage all aspects of the Verifiable Credential service. It offers a way to set up a brand new service, manage and create Verifiable Credential contracts, revoke Verifiable Credentials, and completely opt out of the service.

Whats New

General

- Entra Verified ID is supported on Microsoft GCC environments.

Create A Free Developer Account

Microsoft identity platform

- **Free Microsoft Entra tenant** — [Create a new tenant](~/identity-platform/quickstart-create-new-tenant.md) with an [Azure free account](https://azure.microsoft.com/pricing/purchase-options/azure-account). This gives you Entra ID Free tier. You can then [activate a free trial of Microsoft Entra ID P1 or P2](~/fundamentals/get-started-premium.md) if needed for testing.

Admin Api

Security

Learn how to manage your verifiable credential deployment using Admin API.

Error Codes

Troubleshooting

Reference of error codes for Microsoft Entra Verified ID APIs

Rotate signing keys

General

Learn how to rotate Microsoft Entra Verified ID signing keys.

Upgrade signing keys

General

Learn how to upgrade Microsoft Entra Verified ID signing keys to become FIPS compliant.

Vc Network Api

Developer

Learn how to use the Microsoft Entra Verified ID Network API

Dnsbind

General

Learn how to link your domain to your decentralized identifier (DID).

Use Quickstart

Security

In this article, you learn how to use a quickstart to create a custom verifiable credential for an ID token hint.

Dnsbind

Fundamentals

The domain you verify ownership of to your DID is defined in the [overview section](verifiable-credentials-configure-tenant.md#set-up-verified-id). The domain needs to be a domain under your control and it should be in the format `https://www.contoso.com/`.

Whats New

General

This article lists the latest features, improvements, and changes in the Microsoft Entra Verified ID service.

Idv Partners

Security

| Idemia | [Idemia documentation](https://na.idemia.com/identity/verifiable-credentials/) | Idemia Integration with Microsoft Entra Verified ID enables "Verify once, use everywhere" functionality. |

Admin Api

Security

The Microsoft Entra Verified ID Admin API enables you to manage all aspects of the Verifiable Credential service. It offers a way to set up a brand new service, manage and create Verifiable Credential contracts, revoke Verifiable Credentials and completely opt out the service as well.

Credential Design

Security

The following four attestation types are currently available to be configured in the rules definition. They are different ways of providing claims used by the Microsoft Entra Verified ID issuing service to be inserted into a verifiable credential and attest to that information with your decentralized identifier (DID). Multiple attestation types can be used in the rules definition.

Decentralized Identifier Overview

Fundamentals

In order to be able to resolve DID documents, DIDs are typically recorded on an underlying network of some kind that represents a trust system. Microsoft currently supports DID:Web trust system. DID:Web is a permission based model that allows trust using a web domain’s existing reputation. DID:Web is in support status General Available.

Dnsbind

Fundamentals

The domain you verify ownership of to your DID is defined in the [overview section](verifiable-credentials-configure-tenant.md#set-up-verified-id). The domain needs to be a domain under your control and it should be in the format `https://www.example.com/`.

Error Codes

Troubleshooting

"message": "The request contains `includeQRCode`, but it is not boolean."

How Use Vcnetwork

Security

1. On the start page of **Microsoft Entra Verified ID** in the **Azure portal**, you have a quickstart named **Verification request**. Selecting **start** takes you to a page where you can browse the Verifiable Credentials Network.

Idemia

General

To configure IDEMIA as your identity verification proofing solution, follow these steps:

Issuer Openid

Standards

To receive a verifiable credential, your users need to sign into your IDP from the **Microsoft Authenticator** app.

Issuer Revoke

Security

> If the verifiable credential is old and was issued during the preview period, this claim doesn't exist. Revocation doesn't work for this credential and you have to reissue it.

Opt Out

Security

1. From the **Azure portal**, search for verifiable credentials.

Plan Issuance Solution

Security

All verifiable credentials must declare their *type* in their [rules definition](rules-and-display-definitions-model.md#rulesmodel-type). The credential type distinguishes a verifiable credentials schema from other credentials and it ensures interoperability between issuers and verifiers. To indicate a credential type, provide one or more credential types that the credential satisfies. Each type is a unique string. Often, a URI is used to ensure global uniqueness. The URI doesn't need to be addressable. It's treated as a string. As an example, a diploma credential issued by Contoso University might declare the following types:

Plan Verification Solution

Authentication

:::image type="content" source="media/plan-verification-solution/plan-verification-solution-authenticator.png" alt-text="Diagram of the components of a verification solution with Microsoft Authenticator application highlighted.":::

Register Didwebsite

General

1. Go to the **Verified ID** page in the **Azure portal**.

Services Partners

Developer

You could select a partner from the list and build seamless end-user experiences for onboarding, secure access to critical services, self-service, and custom business application scenarios. If you're a Services or solution Partner and would like to be considered into Microsoft Entra Verified ID partner documentation, submit your application [request](https://forms.microsoft.com/r/AGVsXmf4EZ).

Use Quickstart

Security

In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.

Use Quickstart Idtoken

Security

In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.

Use Quickstart Presentation

Security

In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.

Use Quickstart Selfissued

Security

In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.

Using Facecheck

Security

Face Check is a privacy-respecting facial matching. It allows enterprises to perform high-assurance verifications securely, simply, and at scale. Face Check adds a critical layer of trust by performing facial matching between a user’s real-time selfie and a photo. The facial matching is powered by Azure AI services. Face Check protects user privacy by sharing only the match results and not any sensitive identity data, while allowing organizations to be sure the person claiming an identity is really them.

Using the Microsoft Authenticator with Verified ID

Authentication

In this tutorial, you learn how to install the **Microsoft Authenticator** app and use it for the first time with Verified ID. You use the public end to end demo webapp to issue a verifiable credential to the **Authenticator** and present verifiable credentials from the **Authenticator**.

Using Wallet Library

Microsoft identity platform

- **[Android Studio](https://developer.android.com/studio)** installed on Mac/Windows and an Android test device. You need to enable [developer mode](https://developer.android.com/studio/debug/dev-options) on your Android test device.