Skip to main content
Version: 11.3.0

Advanced Setup

This page covers the platform-level wiring HYPR Affirm depends on: the identity-provider integration prerequisites, the user-directory attributes each verification step reads, and the Entra application strategy decisions that affect every Affirm deployment.

For per-workflow configuration (steps, retries, approvers, outcomes, customizations), see Configuring HYPR Affirm. For an end-to-end first-run tutorial, see Get Started.

Required

At least one Okta or Entra ID integration must be enabled on the tenant. See Integrations for setup instructions.

If no qualifying integration is configured, HYPR Affirm displays a No Integrations Configured dialog the first time you click into the Affirm tab. See No Integrations Configured.

Identity-Provider Attribute Requirements​

HYPR Affirm reads user attributes from the configured Okta or Entra ID integration during a verification flow. The set of attributes required depends on which verification steps the workflow uses. Only a small core of attributes is required for every flow; the rest become required when the steps that read them are enabled.

Always Required​

These attributes must be populated on every target user, regardless of workflow configuration:

AttributeEntra ID fieldOkta field
UsernameUPNUsername

If the username attribute is missing for a user, that user cannot be the requester in any Affirm verification flow.

Required by Step​

These attributes are required only when the corresponding verification step is enabled in the workflow:

AttributeRequired when this step is enabledNotes
Email AddressPhone Number / Email Verification, and approver-invitation flowsUsed for email OTP delivery and approver-invitation emails. Entra ID: Mail / EmailAddress. Okta: Email.
Mobile Phone NumberPhone Number / Email VerificationUsed for SMS OTP delivery
First Name, Last NameDocument and Biometric VerificationUsed for name-comparison against the document
Manager (manager link / ManagerId)Approver type is ManagerEntra ID: Manager field. Okta: ManagerId field
Street AddressLocation step
CityLocation step
StateLocation step
Postal CodeLocation stepCalled Zip code in Okta
Country CodeLocation step

Before exposing Affirm to a user population, confirm the target users have the attributes required by the workflows that apply to them. If a workflow's verification step references an attribute that isn't populated, the step fails at runtime, and what happens next depends on the configured failure outcome.

Enterprise Passkey App Reuse vs. Purpose-Built Affirm App​

When HYPR Enterprise Passkey is deployed for authentication, HYPR Affirm can reuse the existing Entra application from that integration to retrieve user profile data. This is convenient, because no additional app registration is required. However, the Enterprise Passkey app carries Entra permissions (group management, FIDO2 credential management, directory read) that exceed what Affirm alone requires under a least-privilege model.

Keep Enterprise Passkey app reuse when the following apply:

  • Enterprise Passkey is the production authentication method on the tenant
  • No regulatory or organizational policy requires per-product app separation

The Enterprise Passkey app's broader permissions are already justified by the Enterprise Passkey authentication use case, and Affirm uses the same identity surface.

Create a separate, minimal-permission Affirm app when any of the following apply:

  • Enterprise Passkey is not deployed for authentication, so there is no existing app to reuse
  • A regulatory or organizational policy requires per-product app registrations
  • A security review wants the smallest possible permission set per consuming application

For the recommended minimal permission set when Affirm runs without Enterprise Passkey, see Entra ID Application Setup — App Registration Patterns.

No Integrations Configured​

When HYPR Affirm cannot find a qualifying Okta or Entra ID integration on the tenant, it blocks workflow operations and displays the No Integrations Configured dialog the first time you enter the Affirm tab.

Add Application dialog stating there are no eligible applications to connect, with Cancel and Set Up Integration Now buttons

The dialog appears on any attempt to enter Affirm workflow management: viewing the workflow list, opening a workflow or making a configuration change. It has two actions:

  • Set Up Integration Now — opens the Control Center Standard: Integrations options so you can configure an Okta or Entra ID integration
  • Cancel — returns to the HYPR Affirm landing tab, where you can read documentation but cannot make changes

After the integration is created, Affirm picks it up automatically. You do not need a separate step to attach the integration to Affirm. If the dialog persists after the integration is configured, contact your HYPR representative.