Verified Outcome
Verified Outcome defines what happens to the requester after a successful HYPR Affirm verification. Choose one outcome per workflow. The card reads Define the outcome of the requester's identity verification journey upon success. A new flow uses Display verification result to the end user; a CC Admin flow offers only Redirect to Device Manager to register a new login method.
Some outcomes depend on the flow's Application. The TAP and Verified ID outcomes need an Entra ID integration, the Okta password reset outcome needs an Okta integration and the Device Manager outcome needs an application except in a CC Admin flow. Affirm rejects a save that does not meet these conditions.
While the approver reviews, the requester waits on the Almost done! screen: "Verifying your information takes a few minutes. Avoid closing or refreshing your browser. We will notify you as soon as the process is complete. Thank you for your patience." The outcome then applies. If an outcome cannot be produced, the requester sees a message such as "We could not generate your Entra ID TAP (Temporary Access Pass). Please contact your helpdesk for further support."
Redirect to Device Manager to register a new login method
Sends the verified requester to HYPR Device Manager to register a new authentication device. From the Associated RP App ID list, choose the Relying Party application whose Device Manager the requester lands in. To use the workflow's general Application setting instead, leave Use default (no specific RP App) selected.
Issue a Microsoft Entra ID Temporary Access Pass (TAP)
Issues an Entra TAP to the verified requester and shows it on screen after "Your Entra ID TAP (Temporary Access Pass) is: ". Choose Use Entra TAP Lifetime Duration Default (60 minutes) or set Use Custom TAP Lifetime Duration (in minutes) to override.
A custom lifetime must be between 60 and 480 minutes (1 to 8 hours). A value outside that range is rejected when you save the flow. To issue a pass with a shorter or longer lifetime, such as a 10-minute pass, use an Outcome API Call customization. The customization can create the pass directly through the Microsoft Graph API, within the range your Entra TAP policy permits. See Issue a pass outside 60 to 480 minutes.
For Entra app setup, see Entra ID Temporary Access Pass (TAP) for HYPR Affirm.
Issue a Microsoft Verified ID Verifiable Credential (VC)
Issues a Microsoft Verified ID credential to the verified requester. Enter the Authority ID, Manifest Contract ID and Type of the credential to issue; all three are required. The requester sees "Your results have been approved. Please scan the QR code below to continue issuing your Verifiable Credential." with a QR code and, on a phone browser, a link after "or use". After the credential is added, the screen reads "You have successfully added the Verifiable Credential to your wallet!"
For Entra Verified ID setup, see Entra Verified ID for HYPR Affirm.
Redirect to an Okta password reset page
Sends the verified requester to the Okta self-service password reset page. For Okta setup, see Okta Password Reset for HYPR Affirm.
Redirect to URL
Sends the verified requester to a custom URL. Type the destination in the Redirect URL field. For a URL that differs per verification, enter DYNAMIC as the Redirect URL and pass the URL in the redirectUrl field when you create the verification request through the Affirm API. Dynamic URLs are useful when you embed Affirm in an external application; see Create a verification flow in the API reference.
Display verification result to the end user
Shows the verification result directly to the requester at the end of the flow rather than handing off to a downstream system. The requester sees Identity verification approved, "Your results have been approved." and ID Verified under a check mark.
When Helpdesk is enabled for your tenant, you can also select Display Verification Confirmation ID information on approved screen to show the requester a six-digit verification ID that your help desk can use to find the verification. The screen then adds "Please provide the verification ID when contacting your helpdesk." with the ID and a copy button. When an Outcome API Call customization returns content to display, that content replaces the ID.
Related
- Unverified Outcome: what happens when verification fails
- Outcomes and Integration: how outcomes work conceptually and links to IdP-side setup
- Configure Verification Steps: table of all verification steps