Microsoft Entra ID
General

Validate Oidc Multitenant App Gallery

In brief

The documentation now states that applications using Microsoft identity platform v1 endpoints cannot be validated through self-service App Gallery onboarding. It recommends migrating to v2 endpoints.

What Entra admins need to know

Migrate v1 endpoint applications to v2 before starting self-service validation.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Microsoft identity platform v1 endpoints aren't supported

Self-service Microsoft Entra App Gallery onboarding supports applications that use Microsoft identity platform v2 OpenID Connect (OIDC) endpoints.

Applications that use Microsoft identity platform v1 endpoints can't be validated through the self-service onboarding experience. Microsoft recommends migrating to v2 endpoints to take advantage of self-service validation, publishing, and lifecycle management capabilities.

The v2 endpoint uses a scope-based authorization model, including standard OIDC scopes such as openid, profile, and email, and provides a consistent authorization and token model that can be validated through the self-service experience. It also supports capabilities such as incremental consent, allowing applications to request delegated permissions as needed.

Microsoft identity platform v1.0 and v2.0 ID tokens differ in the claims and token semantics they expose. For more information, see ID token claims reference.

Your gallery submission ID

Before you start validation, create your Microsoft Entra gallery submission and copy its Submission ID. You will need this ID to submit your validation results.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…