Using the wizard to set up Entra Verified ID

Rory Braybrook
The new control plane
3 min readMar 7, 2024
Image of a wizard
AI created image of a wizard and a black cat.jpg from Wikimedia

When Verified ID came out, you had to set everything up manually.

Now they have a “wizard” that does it all for you.

Go to the Verified ID blade in Entra.

“If you have a custom domain registered for your Microsoft Entra tenant, you see this Get started option. If you don't have a custom domain registered, either register it before setting up Verified ID or continue using the advanced setup.”

Image of Verified ID home screen with “Get started” button

Click “Get started”.

It took under a minute to set everything up 😃

Image of “Your verified employee credential is now ready”

It adds your tenant’s verified domain.

Then click Step 1, “Get your new credential”.

You log in and then get redirected to your “My Account” page:

https://myaccount.microsoft.com/
Image of the “My Account” page with “Get my Verified ID” button

Click “Get my Verified ID”.

Image of the QR code

Open the Microsoft Authenticator app.

Image of authenticator app with “Verified ID” tab

In the app, click the “Verified ID” tab and then the “Scan QR” button. Then, scan the QR code.

Image of authenticator app with “Add a Verified ID”

Then click “Add”.

Image of authenticator app with with new VC displayed

Your new VC is now displayed.

Back in the portal, let’s try step 2, “Use your new credential”.

We get redirected to the Proseware demo. site:

Image of Proseware site

Click “Access discounts”.

Image of Proseware login page with “Verify my Employee Credential” button

Click “Verify my Employee Credential”.

Image of QR code to scan

Use the authenticator app. to scan the QR code.

Image of authenticator app with “Share with Proseware” screen

Then, “Share” the VC.

Image of Proseware site with discounts applied

You will now be eligible for the discount!

If you want to do the whole thing yourself, the documentation is here.

To see the DID document, the URL is of the form:

did:web:verifiedid.entra.microsoft.com:tenantid:authority-id

You can get the DID URL from the portal:

Image of “Organisation settings” tab showing DID URL

You can use the DIF Universal Resolver to find the DID document:

Image of DIF Universal Resolver showing “DID Document”

Notice that the DID method is “did.web”. Microsoft also supported “did.ion” in the beginning, but there was little uptake, so they deprecated it.

All good!

--

--

Rory Braybrook
The new control plane

NZ Microsoft Identity dude and MVP. Azure AD/B2C/ADFS/Auth0/identityserver. StackOverflow: https://bit.ly/2XU4yvJ Presentations: http://bit.ly/334ZPt5