Do I need a verified domain to federate applications in Entra ID?

Pedro Ignácio 1 Reputation point
2024-03-02T02:47:20.6533333+00:00

I'm trying to integrate an application with my tenant via SAML.

It's one of the applications listed in Entra ID's application gallery. One of the steps required in the tutorial is to verify a domain in the application. As I'm not the owner of the .onmicrosoft.com domain, I'm not able to verify it.

This got me thinking, am I required to have a domain to integrate the applications in my tenant?

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,315 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 144.2K Reputation points MVP
    2024-03-02T16:19:42.1766667+00:00

    If your tenant is going to be the Identity provider , and you need to verify it for the app, then yes you need a verifiable custom domain setup in Entra.

    https://video2.skills-academy.com/en-us/entra/identity/users/domains-manage

    Having said that, you could in theory simply use the onmicrosoft domain you manage as the domain but if the app is requiring proof of ownership, then you really should setup a custom domain as the onmicrosoft.com domain is considered a "fallback domain"

    https://video2.skills-academy.com/en-us/microsoft-365/admin/setup/add-or-replace-your-onmicrosoftcom-domain?view=o365-worldwide

    1 person found this answer helpful.
    0 comments No comments