πŸ“‹ Microsoft Entra Documentation Changes

Changes for June 21st 2025

Period: June 20th 2025, 12:00 AM to June 21st 2025, 12:00 AM

πŸ“š Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on June 21st 2025.

πŸ“Š Summary

60
Total Commits
0
New Files
58
Modified Files
0
Deleted Files
18
Contributors

πŸ“ Modified Documentation Files

+58 / -56 lines changed
Commit: edit pass: authenticate-application-id
Changes:
Before
After
---
title: How to import and export Microsoft Entra Connect configuration settings
description: This article describes frequently asked questions for cloud provisioning.
author: billmath
manager: femila
ms.custom: sfi-ga-nochange
---
 
# Import and export Microsoft Entra Connect configuration settings
 
Microsoft Entra Connect deployments vary from a single forest Express mode installation to complex deployments that synchronize across multiple forests by using custom synchronization rules. Because of the large number of configuration options and mechanisms, it's essential to understand what settings are in effect and be able to quickly deploy a server with an identical configuration. This feature introduces the ability to catalog the configuration of a given synchronization server and import the settings into a new deployment. Different synchronization settings snapshots can be compared to easily visualize the differences between two servers, or the same server over time.
 
Each time the configuration is changed from the Microsoft Entra Connect wizard, a new time-stamped JSON settings file is automatically exported toβ€―**%ProgramData%\AADConnect**. The settings file name is of the form **Applied-SynchronizationPolicy-*.JSON**, where the last part of the file name is a time stamp.
 
> [!IMPORTANT]
> Only changes made by Microsoft Entra Connect are automatically exported. Any changes made by using PowerShell, the Synchronization Service Manager, or the Synchronization Rules Editor must be exported on demand as needed to maintain an up-to-date copy. Export on demand can also be used to place a copy of the settings in a secure location for disaster recovery purposes.
 
>[!NOTE]
>This feature cannot be used if the Microsoft Entra Connect installation was modified to include the G-SQL connector or the G-LDAP connector.
 
---
title: Import and Export Microsoft Entra Connect Configuration Settings
description: This article describes frequently asked questions for cloud provisioning.
author: billmath
manager: femila
ms.custom: sfi-ga-nochange
---
 
# Import and export Microsoft Entra Connect configuration settings
 
Microsoft Entra Connect deployments vary from a single forest Express mode installation to complex deployments that synchronize across multiple forests by using custom synchronization rules. Because of the large number of configuration options and mechanisms, it's essential to understand what settings are in effect and be able to quickly deploy a server with an identical configuration. This feature introduces the ability to catalog the configuration of a specific synchronization server and import the settings into a new deployment. You can compare different synchronization settings snapshots to easily visualize the differences between two servers or the same server over time.
 
Each time the configuration is changed from the Microsoft Entra Connect wizard, a new time-stamped JSON settings file is automatically exported toβ€―`%ProgramData%\AADConnect`. The settings file name is of the form `Applied-SynchronizationPolicy-*.JSON`, where the last part of the file name is a time stamp.
 
> [!IMPORTANT]
> Only changes made by Microsoft Entra Connect are automatically exported. Any changes made by using PowerShell, the Synchronization Service Manager, or the Synchronization Rules Editor must be exported on demand as needed to maintain an up-to-date copy. You can also use export on demand to place a copy of the settings in a secure location for disaster recovery purposes.
 
You can't use this feature if the Microsoft Entra Connect installation was modified to include the G-SQL connector or the G-LDAP connector. You also can't combine this feature when you use an existing Azure Active Directory Synchronization (ADSync) database. The use of import/export configuration and using an existing database are mutually exclusive.
 
<a name='export-azure-ad-connect-settings-'></a>
+1 / -58 lines changed
Commit: removed unapproved models
Changes:
Before
After
ACS FIDO Authenticator NFC|c89e6a38-6c00-5426-5aa5-c9cbf48f0382|&#10060;|&#x2705;|&#x2705;|&#10060;
Allthenticator Android App: roaming BLE FIDO2 Allthenticator for Windows, Mac, Linux, and Allthenticate door readers|5ca1ab1e-fa57-1337-f1d0-a117371ca702|&#x2705;|&#x2705;|&#10060;|&#10060;
Allthenticator iOS App: roaming BLE FIDO2 Allthenticator for Windows, Mac, Linux, and Allthenticate door readers|5ca1ab1e-1337-fa57-f1d0-a117e71ca702|&#x2705;|&#x2705;|&#10060;|&#10060;
Android Authenticator with SafetyNet Attestation|b93fd961-f2e6-462f-b122-82002247de78|&#x2705;|&#10060;|&#10060;|&#10060;
Arculus FIDO 2.1 Key Card \[P71\]|3f59672f-20aa-4afe-b6f4-7e5e916b6d98|&#10060;|&#x2705;|&#x2705;|&#10060;
Arculus FIDO2/U2F Key Card|9d3df6ba-282f-11ed-a261-0242ac120002|&#10060;|&#x2705;|&#x2705;|&#10060;
ATKey.Card CTAP2.0|d41f5a69-b817-4144-a13c-9ebd6d9254d6|&#x2705;|&#x2705;|&#10060;|&#x2705;
Crayonic KeyVault K1 (USB-NFC-BLE FIDO2 Authenticator)|be727034-574a-f799-5c76-0929e0430973|&#x2705;|&#x2705;|&#x2705;|&#x2705;
Cryptnox FIDO2|9c835346-796b-4c27-8898-d6032f515cc5|&#10060;|&#10060;|&#x2705;|&#10060;
Cryptnox FIDO2.1|1d1b4e33-76a1-47fb-97a0-14b10d0933f1|&#10060;|&#10060;|&#x2705;|&#10060;
Dapple Authenticator from Dapple Security Inc.|6dae43be-af9c-417b-8b9f-1b611168ec60|&#10060;|&#x2705;|&#10060;|&#10060;
Deepnet SafeKey/Classic (FP)|e41b42a3-60ac-4afb-8757-a98f2d7f6c9f|&#x2705;|&#x2705;|&#10060;|&#10060;
Deepnet SafeKey/Classic (NFC)|b12eac35-586c-4809-a4b1-d81af6c305cf|&#10060;|&#x2705;|&#x2705;|&#10060;
Deepnet SafeKey/Classic (USB)|b9f6b7b6-f929-4189-bca9-dd951240c132|&#10060;|&#x2705;|&#10060;|&#10060;
Egomet FIDO2 Authenticator for Android|1105e4ed-af1d-02ff-ffff-ffffffffffff|&#x2705;|&#10060;|&#10060;|&#10060;
ellipticSecure MIRkey USB Authenticator|eb3b131e-59dc-536a-d176-cb7306da10f5|&#10060;|&#x2705;|&#10060;|&#10060;
Ensurity AUTH BioPro|454e5346-4944-4ffd-6c93-8e9267193e9b|&#x2705;|&#x2705;|&#10060;|&#10060;
Ensurity ThinC|454e5346-4944-4ffd-6c93-8e9267193e9a|&#x2705;|&#x2705;|&#10060;|&#10060;
ESS Smart Card Inc. Authenticator|5343502d-5343-5343-6172-644649444f32|&#10060;|&#10060;|&#x2705;|&#10060;
eToken Fusion FIPS|050dd0bc-ff20-4265-8d5d-305c4b215192|&#10060;|&#x2705;|&#10060;|&#10060;
ACS FIDO Authenticator NFC|c89e6a38-6c00-5426-5aa5-c9cbf48f0382|&#10060;|&#x2705;|&#x2705;|&#10060;
Allthenticator Android App: roaming BLE FIDO2 Allthenticator for Windows, Mac, Linux, and Allthenticate door readers|5ca1ab1e-fa57-1337-f1d0-a117371ca702|&#x2705;|&#x2705;|&#10060;|&#10060;
Allthenticator iOS App: roaming BLE FIDO2 Allthenticator for Windows, Mac, Linux, and Allthenticate door readers|5ca1ab1e-1337-fa57-f1d0-a117e71ca702|&#x2705;|&#x2705;|&#10060;|&#10060;
Arculus FIDO 2.1 Key Card \[P71\]|3f59672f-20aa-4afe-b6f4-7e5e916b6d98|&#10060;|&#x2705;|&#x2705;|&#10060;
Arculus FIDO2/U2F Key Card|9d3df6ba-282f-11ed-a261-0242ac120002|&#10060;|&#x2705;|&#x2705;|&#10060;
ATKey.Card CTAP2.0|d41f5a69-b817-4144-a13c-9ebd6d9254d6|&#x2705;|&#x2705;|&#10060;|&#x2705;
Crayonic KeyVault K1 (USB-NFC-BLE FIDO2 Authenticator)|be727034-574a-f799-5c76-0929e0430973|&#x2705;|&#x2705;|&#x2705;|&#x2705;
Cryptnox FIDO2|9c835346-796b-4c27-8898-d6032f515cc5|&#10060;|&#10060;|&#x2705;|&#10060;
Cryptnox FIDO2.1|1d1b4e33-76a1-47fb-97a0-14b10d0933f1|&#10060;|&#10060;|&#x2705;|&#10060;
Deepnet SafeKey/Classic (NFC)|b12eac35-586c-4809-a4b1-d81af6c305cf|&#10060;|&#x2705;|&#x2705;|&#10060;
Egomet FIDO2 Authenticator for Android|1105e4ed-af1d-02ff-ffff-ffffffffffff|&#x2705;|&#10060;|&#10060;|&#10060;
Ensurity AUTH BioPro|454e5346-4944-4ffd-6c93-8e9267193e9b|&#x2705;|&#x2705;|&#10060;|&#10060;
Ensurity ThinC|454e5346-4944-4ffd-6c93-8e9267193e9a|&#x2705;|&#x2705;|&#10060;|&#10060;
eToken Fusion FIPS|050dd0bc-ff20-4265-8d5d-305c4b215192|&#10060;|&#x2705;|&#10060;|&#10060;
eToken Fusion NFC FIPS|10c70715-2a9a-4de1-b0aa-3cff6d496d39|&#10060;|&#x2705;|&#x2705;|&#10060;
eToken Fusion NFC PIV|146e77ef-11eb-4423-b847-ce77864e9411|&#10060;|&#x2705;|&#x2705;|&#10060;
eWBM eFA310 FIDO2 Authenticator|95442b2e-f15e-4def-b270-efb106facb4e|&#x2705;|&#x2705;|&#10060;|&#10060;
eWBM eFA320 FIDO2 Authenticator|87dbc5a1-4c94-4dc8-8a47-97d800fd1f3c|&#x2705;|&#x2705;|&#10060;|&#10060;
eWBM eFPA FIDO2 Authenticator|61250591-b2bc-4456-b719-0b17be90bb30|&#x2705;|&#x2705;|&#10060;|&#10060;
Excelsecu eSecu FIDO2 Fingerprint Key|6002f033-3c07-ce3e-d0f7-0ffe5ed42543|&#x2705;|&#x2705;|&#10060;|&#10060;
+37 / -22 lines changed
Commit: Updating images per PR review. Other PM updates.
Changes:
Before
After
---
 
 
# Darwinbox HR integration with Microsoft Entra ID
 
The document provides a step-by-step guide for integrating Darwinbox with Microsoft Entra ID. The steps include establishing a connection, configuring attribute mapping, testing account provisioning, configuring account access rules, and monitoring provisioning. Use this integration to configure cloud-native users directly in Microsoft Entra ID. This integration allows IT admins to automate business processes using Microsoft Entra ID Governance Lifecycle Workflows.
 
Follow these high-level steps for configuring the app integration with Microsoft Entra ID in the Darwinbox Portal.
 
 
## Install connectors in Darwinbox Studio
Open Darwinbox studio and navigate to **Connector Library**. Search for and install the **Microsoft** and **Microsoft Entra** connectors
 
:::image type="content" border="true" source="./media/darwinbox-entra-integration-tutorial/darwinbox-studio.png" alt-text="Screenshot of the Darwinbox Studio.":::
 
## Create single-tenant app registration
Next, create a single-tenant app registration and provide the credentials to Darwinbox so they can perform actions such as creating the provisioning job and sending user data to your Entra tenant.
 
Go to the Entra portal, select **App Registrations**, and then select **New registration**. Create a single-tenant app as shown below.
 
---
 
 
# Integrate Darwinbox HR with Microsoft Entra ID
 
The document provides a step-by-step guide for integrating Darwinbox with Microsoft Entra ID. The steps include establishing a connection, configuring attribute mapping, testing account provisioning, configuring account access rules, and monitoring provisioning. Use this integration to configure cloud-native users directly in Microsoft Entra ID. This integration allows IT admins to automate business processes using Microsoft Entra ID Governance Lifecycle Workflows.
 
Follow these high-level steps for configuring the app integration with Microsoft Entra ID in the Darwinbox Portal.
 
 
## Create single-tenant app registration
In this step, we'll create a single-tenant app registration in Microsoft Entra ID and grant it the necessary permissions so that Darwinbox can use the client credentials of this application to create a provisioning job and send user data to your Microsoft Entra ID tenant.
 
Go to the Microsoft Entra admin center, select **App Registrations**, and then select **New registration**. Create a single-tenant app as shown below.
 
:::image type="content" border="true" source="./media/darwinbox-entra-integration-tutorial/entra-darwinbox-register.png" alt-text="Screenshot of Microsoft Entra ID Register an application page." lightbox="media/darwinbox-entra-integration-tutorial/entra-darwinbox-register.png":::
 
Add the following three Microsoft Graph application permissions to let Darwinbox create the provisioning job: `Application.ReadWrite.OwnedBy`, send user data `SyncrhonizationData-User.Upload.OwnedBy`, and review the provisioning logs `ProvisioningLog.Read.All`.
 
:::image type="content" border="true" source="./media/darwinbox-entra-integration-tutorial/entra-darwinbox-sync.png" alt-text="Screenshot of Microsoft Entra ID registering with Darwinbox." lightbox="media/darwinbox-entra-integration-tutorial/entra-darwinbox-sync.png":::
+29 / -26 lines changed
Commit: June freshness updates
Changes:
Before
After
---
title: Use the AD FS application migration to move AD FS apps to Microsoft Entra ID
description: Learn how to use the AD FS application migration to migrate AD FS relying party applications from ADFS to Microsoft Entra ID. This guided experience provides one-click configuration for basic SAML URLs, claims mapping, and user assignments to integrate the application with Microsoft Entra ID.
author: omondiatieno
manager: mwongerapk
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: how-to
ms.date: 06/10/2024
ms.author: jomondi
ms.reviewer: smriti3
ms.custom: not-enterprise-apps, sfi-image-nochange
#customer intent: As an IT admin currently using AD FS to access applications, I want to migrate my AD FS applications to Microsoft Entra ID using the AD FS application migration wizard, so that I can have a unified experience to discover, evaluate, and configure new Microsoft Entra applications.
---
 
# Use AD FS application migration to move AD FS apps to Microsoft Entra ID
 
In this article, you learn how to migrate your Active Directory Federation Services (AD FS) applications to Microsoft Entra ID using the AD FS application migration.
 
- [Microsoft Entra Connect](https://www.microsoft.com/download/details.aspx?id=47594)
---
title: AD FS application migration to move AD FS apps to Microsoft Entra ID
description: Learn how to use the AD FS application migration to migrate AD FS relying party applications from ADFS to Microsoft Entra ID. This guided experience provides one-click configuration for basic SAML URLs, claims mapping, and user assignments to integrate the application with Microsoft Entra ID.
author: omondiatieno
manager: mwongerapk
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: concept-article
ms.date: 06/20/2025
ms.author: jomondi
ms.reviewer: smriti3
ms.custom: not-enterprise-apps, sfi-image-nochange
#customer intent: As an IT admin currently using AD FS to access applications, I want to migrate my AD FS applications to Microsoft Entra ID using the AD FS application migration wizard, so that I can have a unified experience to discover, evaluate, and configure new Microsoft Entra applications.
---
 
# AD FS application migration to move AD FS apps to Microsoft Entra ID
 
In this article, you learn how to migrate your Active Directory Federation Services (AD FS) applications to Microsoft Entra ID using the AD FS application migration.
 
- [Microsoft Entra Connect](https://www.microsoft.com/download/details.aspx?id=47594)
Modified by Barclay Neira on Jun 20, 2025 12:16 PM
πŸ“– View on learn.microsoft.com
+13 / -13 lines changed
Commit: making accessability improvements
Changes:
Before
After
 
# Using the Microsoft Authenticator with Verified ID
 
In this tutorial, you learn how to install the Microsoft Authenticator app and use it for the first time with Verified ID. You use the public end to end demo webapp to issue a verifiable credential to the Authenticator and present verifiable credentials from the Authenticator.
 
In this article, you learn how to:
 
 
- On iPhone, open the [App Store](https://support.apple.com/HT204266) app and search for **Microsoft Authenticator** and install the app.
 
:::image type="content" source="media/using-authenticator/apple-appstore.png" alt-text="Screenshot of Apple App Store.":::
 
- On Android, open the [Google Play](https://play.google.com/about/howplayworks/) app and search for **Microsoft Authenticator** and install the app.
 
:::image type="content" source="media/using-authenticator/google-play.png" alt-text="Screenshot of Google Play.":::
 
## Use the Microsoft Authenticator for the first time
 
 
1. Open the Authenticator app and press **Accept** on the first screen.
 
# Using the Microsoft Authenticator with Verified ID
 
In this tutorial, you learn how to install the **Microsoft Authenticator** app and use it for the first time with Verified ID. You use the public end to end demo webapp to issue a verifiable credential to the **Authenticator** and present verifiable credentials from the **Authenticator**.
 
In this article, you learn how to:
 
 
- On iPhone, open the [App Store](https://support.apple.com/HT204266) app and search for **Microsoft Authenticator** and install the app.
 
:::image type="content" source="media/using-authenticator/apple-appstore.png" alt-text="Screenshot of Apple App Store search results showing Microsoft Authenticator app with install button.":::
 
- On Android, open the [Google Play](https://play.google.com/about/howplayworks/) app and search for **Microsoft Authenticator** and install the app.
 
:::image type="content" source="media/using-authenticator/google-play.png" alt-text="Screenshot of Google Play Store search results showing Microsoft Authenticator app with install button.":::
 
## Use the Microsoft Authenticator for the first time
 
 
1. Open the Authenticator app and press **Accept** on the first screen.
Modified by Barclay Neira on Jun 20, 2025 12:16 PM
πŸ“– View on learn.microsoft.com
+12 / -12 lines changed
Commit: making accessability improvements
Changes:
Before
After
Authorization: Bearer <token>
 
{
"callback":β€―{
"url":β€―"https://contoso.com/api/issuer/issuanceCallback",
"state": "Aaaabbbb11112222",
"headers":β€―{
"api-key":β€―"an-api-key-can-go-here"
}
},
...
}
```
 
The following permission is required to call the Request Service REST API. For more information, see [Grant permissions to get access tokens](verifiable-credentials-configure-tenant.md#grant-permissions-to-get-access-tokens).
 
 
```json
{
β€―β€―β€―β€―"requestId":β€―"799f23ea-5241-45af-99ad-cf8e5018814e",
Authorization: Bearer <token>
 
{
"callback": {
"url": "https://contoso.com/api/issuer/issuanceCallback",
"state": "Aaaabbbb11112222",
"headers": {
"api-key": "an-api-key-can-go-here"
}
},
...
}
```
 
The following permission is required to call the Request Service REST API. For more information, see [Grant permissions to get access tokens](verifiable-credentials-configure-tenant.md#grant-permissions-to-get-access-tokens).
 
 
```json
{
"requestId": "799f23ea-5241-45af-99ad-cf8e5018814e",
+9 / -9 lines changed
Commit: making accessability improvements
Changes:
Before
After
 
In centralized identity systems, the identity provider (IDP) controls the lifecycle and usage of credentials.
 
:::image type="content" source="./media/introduction-to-verifiable-credentials-architecture/centralized-identity-architecture.png" alt-text="Diagram of an example centralized identity system.":::
 
 
However, there are scenarios where using a decentralized architecture with verifiable credentials can provide value by augmenting key scenarios such as
 
Consider the scenario in the diagram where Proseware, an e-commerce website, wants to offer Woodgrove employees corporate discounts.
 
:::image type="content" source="media/introduction-to-verifiable-credentials-architecture/decentralized-architecture.png" alt-text="Diagram of an example decentralized identity system.":::
 
Terminology for verifiable credentials (VCs) might be confusing if you're not familiar with VCs. The following definitions are from the [Verifiable Credentials Data Model 1.0](https://www.w3.org/TR/vc-data-model/) terminology section. After each, we relate them to entities in the preceding diagram.
 
 
## User journey: Onboarding to Woodgrove
 
:::image type="content" source="media/introduction-to-verifiable-credentials-architecture/onboarding-journey.png" alt-text="Diagram of a user's onboarding journey to Woodgrove.":::
 
**Awareness**: Alice is interested in working for Woodgrove, Inc. and visits Woodgrove’s career website.
 
In centralized identity systems, the identity provider (IDP) controls the lifecycle and usage of credentials.
 
:::image type="content" source="./media/introduction-to-verifiable-credentials-architecture/centralized-identity-architecture.png" alt-text="Architectural diagram showing centralized identity system with identity provider controlling user credentials, applications, and services within a single trust boundary.":::
 
 
However, there are scenarios where using a decentralized architecture with verifiable credentials can provide value by augmenting key scenarios such as
 
Consider the scenario in the diagram where Proseware, an e-commerce website, wants to offer Woodgrove employees corporate discounts.
 
:::image type="content" source="media/introduction-to-verifiable-credentials-architecture/decentralized-architecture.png" alt-text="Architectural diagram showing decentralized identity system with Woodgrove as issuer, Alice as holder, and Proseware as verifier, connected through verifiable credentials and decentralized identifiers.":::
 
Terminology for verifiable credentials (VCs) might be confusing if you're not familiar with VCs. The following definitions are from the [Verifiable Credentials Data Model 1.0](https://www.w3.org/TR/vc-data-model/) terminology section. After each, we relate them to entities in the preceding diagram.
 
 
## User journey: Onboarding to Woodgrove
 
:::image type="content" source="media/introduction-to-verifiable-credentials-architecture/onboarding-journey.png" alt-text="Process flow diagram showing Alice's onboarding journey with Woodgrove, including awareness, activation through QR code, identity verification with Adatum, credential issuance, and presentation to complete application.":::
 
**Awareness**: Alice is interested in working for Woodgrove, Inc. and visits Woodgrove’s career website.
Modified by Barclay Neira on Jun 20, 2025 12:16 PM
πŸ“– View on learn.microsoft.com
+9 / -9 lines changed
Commit: making accessability improvements
Changes:
Before
After
Authorization: Bearer <token>
 
{
"callback":β€―{
β€―β€―β€―β€―β€―β€―"url":β€―"https://contoso.com/api/verifier/presentationCallback",
β€―β€―β€―β€―β€―β€―"state":β€―"00aa00aa-bb11-cc22-dd33-44ee44ee44ee",
β€―β€―β€―β€―β€―β€―"headers":β€―{
β€―β€―β€―β€―β€―β€―β€―β€―"api-key":β€―"an-api-key-can-go-here"
β€―β€―β€―β€―β€―β€―}
β€―β€―β€―β€―},
β€―β€―β€―β€―...
}
```
 
|Property |Type |Description |
|---------|---------|---------|
| `type`| string| The verifiable credential type. The `type` must match the type as defined in the `issuer` verifiable credential manifest (for example, `VerifiedCredentialExpert`). To get the issuer manifest, see [Gather credentials and environment details to set up your sample application](verifiable-credentials-configure-issuer.md). Copy the **Issue credential URL**, open it in a web browser, and check the **id** property. |
| `purpose`| string | Optional. Provide information about the purpose of requesting this verifiable credential. This data isn't used by the Authenticator app. |
| `acceptedIssuers`| string collection | Optional. A collection of issuers' DIDs that could issue the type of verifiable credential that subjects can present. To get your issuer DID, see [Gather credentials and environment details to set up your sample application](verifiable-credentials-configure-issuer.md), and copy the value of the **Decentralized identifier (DID)**. If the `acceptedIssuers` collection is empty or not present, then the presentation request accepts a credential type issued by any issuer. |
| `configuration.validation` | [Configuration.Validation](#configurationvalidation-type) | Optional settings for presentation validation.|
Authorization: Bearer <token>
 
{
"callback": {
"url": "https://contoso.com/api/verifier/presentationCallback",
"state": "00aa00aa-bb11-cc22-dd33-44ee44ee44ee",
"headers": {
"api-key": "an-api-key-can-go-here"
}
},
...
}
```
 
|Property |Type |Description |
|---------|---------|---------|
| `type`| string| The verifiable credential type. The `type` must match the type as defined in the `issuer` verifiable credential manifest (for example, `VerifiedCredentialExpert`). To get the issuer manifest, see [Gather credentials and environment details to set up your sample application](verifiable-credentials-configure-issuer.md). Copy the **Issue credential URL**, open it in a web browser, and check the **id** property. |
| `purpose`| string | Optional. Provide information about the purpose of requesting this verifiable credential. This data isn't used by the **Authenticator** app. |
| `acceptedIssuers`| string collection | Optional. A collection of issuers' DIDs that could issue the type of verifiable credential that subjects can present. To get your issuer DID, see [Gather credentials and environment details to set up your sample application](verifiable-credentials-configure-issuer.md), and copy the value of the **Decentralized identifier (DID)**. If the `acceptedIssuers` collection is empty or not present, then the presentation request accepts a credential type issued by any issuer. |
| `configuration.validation` | [Configuration.Validation](#configurationvalidation-type) | Optional settings for presentation validation.|
+10 / -7 lines changed
Commit: June 19 completed revisions for new Win client
Changes:
Before
After
description: The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
ms.service: global-secure-access
ms.topic: how-to
ms.date: 06/18/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: dougeby
 
## Prerequisites
 
- A Microsoft Entra tenant that's onboarded to Global Secure Access.
- A managed device that's joined to the onboarded tenant. The device must be either Microsoft Entra joined or Microsoft Entra hybrid joined.
- Microsoft Entra registered devices aren't supported.
- The Global Secure Access client needs a 64-bit version of Windows 10 or Windows 11, or an Arm64 version of Windows 11.
- Azure Virtual Desktop single-session is supported.
:::image type="content" source="media/how-to-install-windows-client/global-secure-access-client-installed-connected.png" alt-text="Screenshot showing the client is connected.":::
 
## Client interface
To open the Global Secure Access client interface, select the Global Secure Access icon in the system tray. The client interface provides a view of the current connection status, the channels configured for the client, and access to diagnostics tools.
 
description: The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
ms.service: global-secure-access
ms.topic: how-to
ms.date: 06/19/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: dougeby
 
## Prerequisites
 
- A Microsoft Entra tenant onboarded to Global Secure Access.
- A managed device joined to the onboarded tenant. The device must be either Microsoft Entra joined or Microsoft Entra hybrid joined.
- Microsoft Entra registered devices aren't supported.
- The Global Secure Access client needs a 64-bit version of Windows 10 or Windows 11, or an Arm64 version of Windows 11.
- Azure Virtual Desktop single-session is supported.
:::image type="content" source="media/how-to-install-windows-client/global-secure-access-client-installed-connected.png" alt-text="Screenshot showing the client is connected.":::
 
## Client interface
To open the Global Secure Access client interface, select the Global Secure Access icon in the system tray. The client interface provides a view of the current connection status, the channels configured for the client, and access to diagnostics tools.
 
Modified by Barclay Neira on Jun 20, 2025 12:16 PM
πŸ“– View on learn.microsoft.com
+8 / -8 lines changed
Commit: making accessability improvements
Changes:
Before
After
 
Face Check is a privacy-respecting facial matching. It allows enterprises to perform high-assurance verifications securely, simply, and at scale. Face Check adds a critical layer of trust by performing facial matching between a user’s real-time selfie and a photo. The facial matching is powered by Azure AI services. Face Check protects user privacy by sharing only the match results and not any sensitive identity data, while allowing organizations to be sure the person claiming an identity is really them.
 
:::image type="content" source="media/using-facecheck/verify-confirm-review.png" alt-text="Screenshot of using Face Check.":::
 
## Prerequisites
 
### Setting up Face Check with Microsoft Entra Verified ID in the Admin Center
1. In the Verified ID overview page, scroll down to the new Add-ons section and `Enable` the Face Check add-on.
 
:::image type="content" source="media/using-facecheck/face-check-add-on.png" alt-text="Screenshot of the Face Check add-on.":::
 
2. In the Link a subscription step, select a Subscription, a Resource group, and the Resource location. Then select `Validate`. If there are no subscriptions listed, see [What if I can't find a subscription?](using-facecheck.md#what-if-i-cant-find-a-subscription)
 
:::image type="content" source="media/using-facecheck/face-check-subscription-linking.png" alt-text="Screenshot subscription linking for Face Check.":::
 
3. Once validated you can `Enable` the add-on.
 
:::image type="content" source="media/using-facecheck/face-check-add-on-enabled.png" alt-text="Screenshot Face Check add-on enabled.":::
 
 
Face Check is a privacy-respecting facial matching. It allows enterprises to perform high-assurance verifications securely, simply, and at scale. Face Check adds a critical layer of trust by performing facial matching between a user’s real-time selfie and a photo. The facial matching is powered by Azure AI services. Face Check protects user privacy by sharing only the match results and not any sensitive identity data, while allowing organizations to be sure the person claiming an identity is really them.
 
:::image type="content" source="media/using-facecheck/verify-confirm-review.png" alt-text="Screenshot of Microsoft Authenticator Face Check verification flow showing verify, confirm, and review steps with facial recognition interface.":::
 
## Prerequisites
 
### Setting up Face Check with Microsoft Entra Verified ID in the Admin Center
1. In the Verified ID overview page, scroll down to the new Add-ons section and `Enable` the Face Check add-on.
 
:::image type="content" source="media/using-facecheck/face-check-add-on.png" alt-text="Screenshot of Microsoft Entra Verified ID overview page showing Face Check add-on in Add-ons section with Enable button.":::
 
2. In the Link a subscription step, select a Subscription, a Resource group, and the Resource location. Then select `Validate`. If there are no subscriptions listed, see [What if I can't find a subscription?](using-facecheck.md#what-if-i-cant-find-a-subscription)
 
:::image type="content" source="media/using-facecheck/face-check-subscription-linking.png" alt-text="Screenshot of Face Check subscription linking dialog showing dropdown menus for Subscription, Resource group, and Resource location with Validate button.":::
 
3. Once validated you can `Enable` the add-on.
 
:::image type="content" source="media/using-facecheck/face-check-add-on-enabled.png" alt-text="Screenshot of Face Check add-on configuration showing successful validation with Enable button to activate the service.":::
 
Modified by Barclay Neira on Jun 20, 2025 12:16 PM
πŸ“– View on learn.microsoft.com
+6 / -8 lines changed
Commit: making accessability improvements
Changes:
Before
After
 
The Microsoft Entra Verified ID Admin API enables you to manage all aspects of the Verifiable Credential service. It offers a way to set up a brand new service, manage and create Verifiable Credential contracts, revoke Verifiable Credentials and completely opt out the service as well.
 
> The API is intended for developers comfortable with RESTful APIs and enough permissions on the Microsoft Entra tenant to enable the service
 
## Base URL
 
 
#### Return message
 
```
HTTP/1.1 201 Created
Content-type: application/json
 
 
#### Response message
 
```
HTTP/1.1 200 OK
Content-type: application/json
 
The Microsoft Entra Verified ID Admin API enables you to manage all aspects of the Verifiable Credential service. It offers a way to set up a brand new service, manage and create Verifiable Credential contracts, revoke Verifiable Credentials and completely opt out the service as well.
 
> [!NOTE]
> The API is intended for developers comfortable with RESTful APIs and enough permissions on the Microsoft Entra tenant to enable the service.
 
## Base URL
 
 
#### Return message
 
```json
HTTP/1.1 201 Created
Content-type: application/json
 
 
#### Response message
 
```json
HTTP/1.1 200 OK
Modified by Barclay Neira on Jun 20, 2025 12:16 PM
πŸ“– View on learn.microsoft.com
+7 / -7 lines changed
Commit: making accessability improvements
Changes:
Before
After
 
To configure IDEMIA as your identity verification proofing solution, follow these steps:
 
1. In the Microsoft Entra admin center, locate **Verified ID** in the left hand menu and select `Overview`.
1. Select `Explore` and select `Verification request`.
1. Choose `Select issuer(s)` and select `Select first issuer`.
1. Look for `IDEMIA` in the search/select issuers drop down.
1. Select `VerifiedIdentity` as the credential type.
1. Select **Add** and then select review.
1. Download the request body and copy/paste the POST API request URL
 
## Developer steps
## Next steps
 
- [Verifiable credentials admin API](admin-api.md)
- [Request Service REST API issuance specification](issuance-request-api.md)
 
To configure IDEMIA as your identity verification proofing solution, follow these steps:
 
1. In the Microsoft Entra admin center, locate **Verified ID** in the left hand menu and select **Overview**.
1. Select **Explore** and select **Verification request**.
1. Choose **Select issuer(s)** and select **Select first issuer**.
1. Look for **IDEMIA** in the search/select issuers drop down.
1. Select **VerifiedIdentity** as the credential type.
1. Select **Add** and then select **Review**.
1. Download the request body and copy/paste the POST API request URL
 
## Developer steps
## Next steps
 
- [Verifiable credentials admin API](admin-api.md)
- [Request Service REST API issuance specification](issuance-request-api.md)
+6 / -6 lines changed
Commit: June freshness updates
Changes:
Before
After
---
title: Manage consent to applications and evaluate consent requests
description: Learn how to manage consent requests when user consent is restricted, and evaluate a request for tenant-wide admin consent to an app in Microsoft Entra ID.
 
author: omondiatieno
manager: mwongerapk
ms.subservice: enterprise-apps
 
ms.topic: concept-article
ms.date: 06/27/2024
ms.author: jomondi
ms.reviewer: phsignor
ms.custom: enterprise-apps
#customer intent: As an administrator, I want to manage consent to applications and evaluate consent requests, so that I can ensure that only apps from verified publishers and selected permissions are allowed. This helps to minimize security risks and prevent the use of unmanaged accounts in third-party applications.
---
 
# Manage consent to applications and evaluate consent requests
 
Microsoft recommends that you [restrict user consent](~/identity/enterprise-apps/configure-user-consent.md) to allow users to consent only for apps from verified publishers, and only for permissions that you select. For apps that don't meet these criteria, the decision-making process is centralized with your organization's security and identity administrator team.
 
---
title: Application consent management and evaluation of consent requests
description: Understand consent request evaluation and tenant-wide admin consent in Microsoft Entra ID. Essential guidance for administrators managing application permissions and security.
 
author: omondiatieno
manager: mwongerapk
ms.subservice: enterprise-apps
 
ms.topic: concept-article
ms.date: 06/20/2025
ms.author: jomondi
ms.reviewer: phsignor
ms.custom: enterprise-apps
#customer intent: As an administrator, I want to manage consent to applications and evaluate consent requests, so that I can ensure that only apps from verified publishers and selected permissions are allowed. This helps to minimize security risks and prevent the use of unmanaged accounts in third-party applications.
---
 
# Application consent management and evaluation of consent requests
 
Microsoft recommends that you [restrict user consent](~/identity/enterprise-apps/configure-user-consent.md) to allow users to consent only for apps from verified publishers, and only for permissions that you select. For apps that don't meet these criteria, the decision-making process is centralized with your organization's security and identity administrator team.
 
Modified by Barclay Neira on Jun 20, 2025 12:16 PM
πŸ“– View on learn.microsoft.com
+6 / -6 lines changed
Commit: making accessability improvements
Changes:
Before
After
 
To take advantage of the consumptive billing, your Verified ID authority must be linked to an Azure subscription.
 
|If your Verified ID authority is: |You need to: |
|---------|---------|
| A Verified ID authority not yet linked to a subscription | [Link your Verified ID authority to an Azure subscription](#link-your-verified-id-authority-to-a-subscription) to activate consumptive billing. |
| A Verified ID authority linked to a subscription | Do nothing. You're automatically billed monthly for Face Check verifications. |
 
Verified ID generates individual billing events for each unique verification performed by the platform. Whether that verification succeeds or fails. The following matrix provides further clarity on Face Check verification scenarios that are billed:
 
|Face Check Verification scenario |Emits billing event </br>(yes/no) |
|---------|---------|
| Verification request fails after reading QR Code | No|
| Verification request returns service error: The Verified ID service is unable to process the verification request | No |
 
## Link your Verified ID authority to a subscription
 
1. Go to the Verified ID overview page. Scroll down to the new Add-ons section and `Enable` the Face Check add-on
:::image type="content" source="media/using-facecheck/face-check-add-on.png" alt-text="Screenshot of the Face Check add-on.":::
 
 
To take advantage of the consumptive billing, your Verified ID authority must be linked to an Azure subscription.
 
|**If your Verified ID authority is:** |**You need to:** |
|---------|---------|
| A Verified ID authority not yet linked to a subscription | [Link your Verified ID authority to an Azure subscription](#link-your-verified-id-authority-to-a-subscription) to activate consumptive billing. |
| A Verified ID authority linked to a subscription | Do nothing. You're automatically billed monthly for Face Check verifications. |
 
Verified ID generates individual billing events for each unique verification performed by the platform. Whether that verification succeeds or fails. The following matrix provides further clarity on Face Check verification scenarios that are billed:
 
|**Face Check Verification scenario** |**Emits billing event </br>(yes/no)** |
|---------|---------|
| Verification request fails after reading QR Code | No|
| Verification request returns service error: The Verified ID service is unable to process the verification request | No |
 
## Link your Verified ID authority to a subscription
 
1. Go to the **Verified ID** overview page. Scroll down to the new **Add-ons** section and **Enable** the Face Check add-on
:::image type="content" source="media/using-facecheck/face-check-add-on.png" alt-text="Screenshot of the Face Check add-on.":::
 
+6 / -6 lines changed
Commit: added FAQ about SSO
Changes:
Before
After
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 03/04/2025
ms.author: justinha
author: mjsantani
manager: dougeby
 
## Frequently asked questions
 
**Is registration campaign available for MFA Server?**
 
No, the registration campaign is available only for users using Microsoft Entra multifactor authentication.
 
**Can users be nudged within an application?**
 
Yes, we support embedded browser views in certain applications. We don't nudge users in out of the box experiences or in browser views embedded in Windows settings.
 
**Can users be nudged on a mobile device?**
 
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 06/19/2025
ms.author: justinha
author: mjsantani
manager: dougeby
 
## Frequently asked questions
 
**Can users be nudged within an application?**
 
Yes, we support embedded browser views in certain applications. We don't nudge users in out-of-the-box experiences or in browser views embedded in Windows settings.
 
**Can users be nudged within a single sign-on (SSO) session?**
Nudge doesn't trigger if the user is already signed in with SSO. In an SSO session, the user is already authenticated. The registration campaign works only after the user completes MFA.
 
**Can users be nudged on a mobile device?**