Share via

Do I need a verified domain to federate applications in Entra ID?

Pedro Ignácio 1 Reputation point MVP
2024-03-02T02:47:20.6533333+00:00

I'm trying to integrate an application with my tenant via SAML.

It's one of the applications listed in Entra ID's application gallery. One of the steps required in the tutorial is to verify a domain in the application. As I'm not the owner of the .onmicrosoft.com domain, I'm not able to verify it.

This got me thinking, am I required to have a domain to integrate the applications in my tenant?

Microsoft Security | Active Directory Federation Services
Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. Andy David - MVP 160.3K Reputation points MVP Volunteer Moderator
    2024-03-02T16:19:42.1766667+00:00

    If your tenant is going to be the Identity provider , and you need to verify it for the app, then yes you need a verifiable custom domain setup in Entra.

    https://learn.microsoft.com/en-us/entra/identity/users/domains-manage

    Having said that, you could in theory simply use the onmicrosoft domain you manage as the domain but if the app is requiring proof of ownership, then you really should setup a custom domain as the onmicrosoft.com domain is considered a "fallback domain"

    https://learn.microsoft.com/en-us/microsoft-365/admin/setup/add-or-replace-your-onmicrosoftcom-domain?view=o365-worldwide

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.