author: justinha
Verified ID revocation guidance flags a preview-era credential limitation; 21 June otherwise signals documentation maintenance
The 21 June 2025 feed contains 58 updated items, with no new or removed entries and no Message Center notices. Verified ID accounts for 37 updates, but the supplied evidence does not establish a feature launch, preview or general-availability transition, retirement, or tenant-side behavior change. The clearest administrator-relevant items are an operational revocation caveat, refreshed consent and migration guidance, and a billing prerequisite.
- Verified ID revocation guidance flags preview-era credentials
Verified ID · Security
The updated Issuer Revoke page says an older credential issued during the preview period may lack the claim needed for revocation; revocation does not work for that credential and it must be reissued. This is an operational documentation clarification, not a newly announced revocation feature.
- Entra consent guidance refreshed around admin consent
Entra ID · Security
The updated Application consent management article covers evaluation of consent requests and tenant-wide admin consent for application permissions. It is security guidance for permission reviewers; no new consent setting or enforcement behavior is specified.
- Verified ID pricing guidance states the billing prerequisite
Verified ID · General
The updated Verified ID Pricing page says the authority must be linked to an Azure subscription to use consumptive billing. Verify that linkage for deployments relying on that billing model; the evidence does not indicate a price change.
- AD FS migration guidance documents guided SAML setup
Entra ID · Standards
The updated migration article describes moving AD FS relying-party applications to Entra ID through a guided experience, including one-click configuration for basic SAML URLs, claims mapping, and user assignments. Treat this as migration documentation, not proof of a new release or availability change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
58 updates
Microsoft Entra ID
16 updatesMfa Registration Campaign
Updatedauthor: mjsantani
manager: mwongerapk
Howto Mfa Mfasettings
Updatedauthor: justinha
Fido2 Hardware Vendor
UpdatedACS FIDO Authenticator NFC|c89e6a38-6c00-5426-5aa5-c9cbf48f0382|❌|✅|✅|❌
Configure Linked Sign On
Updatedmanager: mwongerapk
Configure User Consent
Updated:::zone-end
Mysdworxcom Tutorial
UpdatedYou can configure and test Microsoft Entra single sign-on for my.sdworx.com in a test environment (my.acc.sdworx.com) but not by using the gallery app (import SP metadata, to be provided by your my.sdworx.com contact). My.sdworx.com supports **IDP** and **SP** initiated single sign-on.
Appneta Tutorial
Updated| Email | user.userprincipalname |
| --- | --- |
Understand consent request evaluation and tenant-wide admin consent in Microsoft Entra ID. Essential guidance for administrators managing application permissions and security.
1. **[Configure Microsoft Entra SSO](#configure-microsoft-entra-sso)** - to enable your users to use this feature.
Learn how to use the AD FS application migration to migrate AD FS relying party applications from ADFS to Microsoft Entra ID. This guided experience provides one-click configuration for basic SAML URLs, claims mapping, and user assignments to integrate the application with Microsoft Entra ID.
Debug SAML-based single sign-on to applications in Microsoft Entra ID.
The document provides a step-by-step guide for integrating Darwinbox with Microsoft Entra ID. The steps include establishing a connection, configuring attribute mapping, testing account provisioning, configuring account access rules, and monitoring provisioning. Use this integration to configure cloud-native users directly in Microsoft Entra ID. This integration allows IT admins to automate business processes using Microsoft Entra ID Governance Lifecycle Workflows.
This article describes frequently asked questions for cloud provisioning.
Microsoft Entra External ID
1 update21790
Updated- [Cross-tenant access overview](../../external-id/cross-tenant-access-overview.md)
Microsoft Entra Verified ID
37 updatesUse Quickstart Idtoken
UpdatedIn the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.
Issuer Revoke
Updated> If the verifiable credential is old and was issued during the preview period, this claim doesn't exist. Revocation doesn't work for this credential and you have to reissue it.
Use Quickstart
UpdatedIn the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.
Use Quickstart Presentation
UpdatedIn the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.
Use Quickstart Selfissued
UpdatedIn the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.
Using Facecheck
UpdatedFace Check is a privacy-respecting facial matching. It allows enterprises to perform high-assurance verifications securely, simply, and at scale. Face Check adds a critical layer of trust by performing facial matching between a user’s real-time selfie and a photo. The facial matching is powered by Azure AI services. Face Check protects user privacy by sharing only the match results and not any sensitive identity data, while allowing organizations to be sure the person claiming an identity is really them.
Admin Api
UpdatedThe Microsoft Entra Verified ID Admin API enables you to manage all aspects of the Verifiable Credential service. It offers a way to set up a brand new service, manage and create Verifiable Credential contracts, revoke Verifiable Credentials and completely opt out the service as well.
Verifiable Credentials Faq
Updated1. In the [Azure portal](https://portal.azure.com), go to **Microsoft Entra ID** for the subscription you use for your Microsoft Entra Verified ID deployment.
To set up Verified ID, follow these steps:
| `type` | string (array) | a list of verifiable credential types this contract can issue |
Credential Design
UpdatedThe following four attestation types are currently available to be configured in the rules definition. They are different ways of providing claims used by the Microsoft Entra Verified ID issuing service to be inserted into a verifiable credential and attest to that information with your decentralized identifier (DID). Multiple attestation types can be used in the rules definition.
In this step, you create the verified credential expert card by using Microsoft Entra Verified ID. After you create the credential, your Microsoft Entra tenant can issue it to users who initiate the process.
How Use Vcnetwork
Updated1. On the start page of **Microsoft Entra Verified ID** in the **Azure portal**, you have a quickstart named **Verification request**. Selecting **start** takes you to a page where you can browse the Verifiable Credentials Network.
Opt Out
Updated1. From the **Azure portal**, search for verifiable credentials.
Plan Issuance Solution
UpdatedAll verifiable credentials must declare their *type* in their [rules definition](rules-and-display-definitions-model.md#rulesmodel-type). The credential type distinguishes a verifiable credentials schema from other credentials and it ensures interoperability between issuers and verifiers. To indicate a credential type, provide one or more credential types that the credential satisfies. Each type is a unique string. Often, a URI is used to ensure global uniqueness. The URI doesn't need to be addressable. It's treated as a string. As an example, a diploma credential issued by Contoso University might declare the following types:
Create a client secret for the registered application you created. The sample application uses the client secret to prove its identity when it requests tokens.
Issuance Request Api
UpdatedAuthorization: Bearer <token>
Presentation Request Api
UpdatedAuthorization: Bearer <token>
Get Started Request Api
UpdatedIssuance request using the `idTokenHint` attestation flow:
Vc Network Api
UpdatedServices Partners
UpdatedYou could select a partner from the list and build seamless end-user experiences for onboarding, secure access to critical services, self-service, and custom business application scenarios. If you're a Services or solution Partner and would like to be considered into Microsoft Entra Verified ID partner documentation, submit your application [request](https://forms.microsoft.com/r/AGVsXmf4EZ).
Whats New
UpdatedApplications that use the Microsoft Entra Verified ID service must use the Request API endpoint that corresponds to their Microsoft Entra tenant's region.
Idemia
UpdatedTo configure IDEMIA as your identity verification proofing solution, follow these steps:
Verified Id Pricing
UpdatedTo take advantage of the consumptive billing, your Verified ID authority must be linked to an Azure subscription.
Partner Gallery
UpdatedHeader: Algorithm and Token type
Register Didwebsite
Updated1. Go to the **Verified ID** page in the **Azure portal**.
Partner Vu
UpdatedIn this tutorial, you learn how to install the **Microsoft Authenticator** app and use it for the first time with Verified ID. You use the public end to end demo webapp to issue a verifiable credential to the **Authenticator** and present verifiable credentials from the **Authenticator**.
Issuer Openid
UpdatedTo receive a verifiable credential, your users need to sign into your IDP from the **Microsoft Authenticator** app.
Plan Verification Solution
Updated:::image type="content" source="media/plan-verification-solution/plan-verification-solution-authenticator.png" alt-text="Diagram of the components of a verification solution with Microsoft Authenticator application highlighted.":::
In order to be able to resolve DID documents, DIDs are typically recorded on an underlying network of some kind that represents a trust system. Microsoft currently supports DID:Web trust system. DID:Web is a permission based model that allows trust using a web domain’s existing reputation. DID:Web is in support status General Available.
Dnsbind
UpdatedThe domain you verify ownership of to your DID is defined in the [overview section](verifiable-credentials-configure-tenant.md#set-up-verified-id). The domain needs to be a domain under your control and it should be in the format `https://www.example.com/`.
In centralized identity systems, the identity provider (IDP) controls the lifecycle and usage of credentials.
Using Wallet Library
Updated- **[Android Studio](https://developer.android.com/studio)** installed on Mac/Windows and an Android test device. You need to enable [developer mode](https://developer.android.com/studio/debug/dev-options) on your Android test device.
Microsoft Entra Verified ID supports the following open standards:
Error Codes
Updated"message": "The request contains `includeQRCode`, but it is not boolean."
Microsoft Entra Workload ID
1 updateOverview
Updated- A service principal of a special type is created in Microsoft Entra ID for the identity. The service principal is tied to the lifecycle of that Azure resource. When the Azure resource is deleted, Azure automatically deletes the service principal for you.
Microsoft Entra Global Secure Access
3 updatesInstall Windows Client
UpdatedThe Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
Next, we activate group membership using the Microsoft Entra admin center, and then attempt to connect with the new role activated.
Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.
