Skip to main content
Version: 11.3.0

Entra ID Application Setup for HYPR Affirm

When HYPR Affirm uses Entra ID-based outcomes or requires Entra as a directory source, it calls Microsoft Graph through an Entra app registration. The permissions required depend on which Affirm features you are enabling.

Relationship with HYPR Enterprise Passkey

If HYPR Enterprise Passkey is already deployed in your organization, an Entra integration and app registration likely already exist. You can reuse that registration or create a purpose-built one for Affirm. The Enterprise Passkey app registration includes permissions for FIDO2 credential provisioning and group management that Affirm alone does not need. A separate, purpose-built registration limits the scope of access to what Affirm requires.

If Enterprise Passkey is not deployed, create an Entra app registration before configuring any Entra-based Affirm outcomes.

When multiple Affirm integrations require Entra access, you can use a single app registration covering all required permissions or create separate registrations scoped to individual features. See App Registration Patterns for approaches including read/write separation and full separation of duties.

Prerequisites​

  • A Microsoft Entra tenant
  • An administrator account with permission to register applications and grant admin consent

Register an Entra Application​

These steps apply regardless of which Affirm integration you are configuring.

  1. Sign in to the Microsoft Entra admin center.
  2. Go to Entra ID > App registrations.
  3. Click New registration.
  4. Enter an application name such as HYPRAffirm.
  5. Select Accounts in this organizational directory only.
  6. Complete the registration.
  7. On the application Overview page, note the Application (client) ID and Directory (tenant) ID. You enter these values in HYPR Control Center when you add the integration.
App registration Overview page with the Essentials section showing the Application (client) ID and Directory (tenant) ID

API Permissions by Integration​

The default User.Read (Delegated) permission is present on all new app registrations and must be retained. The additional permissions required depend on which Affirm feature you are configuring.

To add each Microsoft Graph permission listed in the following sections:

  1. Open the app registration and go to API permissions.
  2. Retain the default User.Read (Delegated) permission, and click + Add a permission.
  3. Select Microsoft Graph.
  4. Select Delegated permissions or Application permissions, as indicated in the table.
  5. Find the permission, and click Add permissions.

Delegated and Application permissions must be added in separate + Add a permission flows.

After adding all required permissions, grant admin consent. Entra Verified ID permissions use a different path; see Entra Verified ID.

Directory Source​

For Affirm to retrieve user profile data from Entra, the app registration requires the following permissions.

PermissionTypePurpose
User.ReadDelegatedSign in and read user profile
User.Read.AllApplicationRead all users' full profiles
Configured permissions showing Microsoft Graph User.Read Delegated and User.Read.All Application, both granted

Temporary Access Pass Outcome​

For Affirm to issue a Temporary Access Pass, the app registration requires the following permissions in addition to User.Read.

PermissionTypePurpose
Directory.Read.AllApplicationRead directory data
User.Read.AllApplicationRead all users' full profiles
UserAuthenticationMethod.ReadWrite.AllApplicationRead and write all users' authentication methods

Add all three as Application permissions.

Delegated by default

Entra ID sometimes skips the permission-type selection screen and assumes Delegated. If this happens, confirm the permission type after admin consent is granted.

For the complete TAP setup including enabling the TAP policy and HYPR Control Center configuration, see Entra ID Temporary Access Pass (TAP) for HYPR Affirm.

Entra Verified ID​

The required permission depends on which Entra Verified ID action the Affirm outcome performs.

For Affirm to issue Entra Verified ID credentials, the app registration requires the following permission.

PermissionTypePurpose
VerifiableCredential.Create.IssueRequestDelegatedIssue Verified ID credentials

For Affirm to present (verify) Entra Verified ID credentials as a verification step, the app registration requires the following permission.

PermissionTypePurpose
VerifiableCredential.Create.PresentRequestDelegatedPresent Verified ID credentials

Both permissions are under Verifiable Credentials Service Request on the APIs my organization uses tab, not under Microsoft Graph. To add them:

  1. Open the app registration and go to API permissions.

  2. Click + Add a permission.

  3. Click the APIs my organization uses tab.

    Request API permissions panel on the APIs my organization uses tab, filtered to the Verifiable Credentials services
  4. Use the filter to locate Verifiable Credentials Service Request, and click it.

  5. Select Delegated permissions.

  6. Select VerifiableCredential.Create.IssueRequest, VerifiableCredential.Create.PresentRequest or both, depending on your workflow.

  7. Click Add permissions.

    Request API permissions for Verifiable Credentials Service Request with Delegated permissions and VerifiableCredential.Create.IssueRequest selected

If a workflow both issues and presents credentials, grant both. The following shows a fully configured app registration with Verifiable Credentials permissions.

Configured permissions listing granted Verifiable Credentials Service, Service Admin and Service Request permissions

For issuing credentials as an Affirm outcome, see Entra Verified ID for HYPR Affirm. For presenting credentials as a verification step, see Identity Verification via Verified Credentials.

After adding all required permissions:

  1. On the API permissions page, click Grant admin consent for [tenant name].
  2. Confirm the prompt.
Grant admin consent confirmation prompt with Yes and No buttons

Permissions marked Yes in the Admin consent required column take effect only after admin consent is granted.

Create a Client Secret​

HYPR can authenticate to Microsoft Graph using either a client secret or a client certificate. To create a client secret:

  1. Open the app registration.

  2. Select Certificates & secrets.

  3. Click New client secret.

    Certificates and secrets page with the Add a client secret panel showing Description and Expires fields
  4. Enter a description and choose an expiration period.

  5. Click Add.

  6. Copy and save the secret value immediately.

    Client secrets tab with a new secret, its value hidden and the Copy to clipboard button highlighted
One time only

The secret value is visible only immediately after creation. If you navigate away, you must create a new secret.

App Registration Patterns​

When HYPR is deployed without Enterprise Passkey, or when strict permission scoping is required, create separate app registrations for different Affirm operations. The following patterns describe the approaches.

Shared requirements

Regardless of which option you choose, any app registration used by HYPR Affirm to retrieve user profile data requires:

  • User.Read (Delegated)
  • User.Read.All (Application)

Option A: Two App Registrations (Read and Write)​

Option A uses the following two app registrations.

App namePermissionsPurpose
HYPRAffirmReadUser.Read (Delegated), User.Read.All (Application)Retrieve user profile data
HYPRAffirmWriteUser.Read (Delegated), User.Read.All (Application), Directory.Read.All (Application), UserAuthenticationMethod.ReadWrite.All (Application), VerifiableCredential.Create.IssueRequest (Delegated), VerifiableCredential.Create.PresentRequest (Delegated)Issue TAPs, issue and present Entra Verified ID credentials

The following shows the configured permissions for HYPRAffirmRead.

Configured permissions showing Microsoft Graph User.Read Delegated and User.Read.All Application, both granted

Option B: Separate Entra Verified ID from TAP​

Option B uses the following three app registrations.

App namePermissionsPurpose
HYPRAffirmReadUser.Read (Delegated), User.Read.All (Application)Retrieve user profile data
HYPRAffirmTAPUser.Read (Delegated), User.Read.All (Application), Directory.Read.All (Application), UserAuthenticationMethod.ReadWrite.All (Application)Issue TAPs
HYPRAffirmVCVerifiableCredential.Create.IssueRequest (Delegated), VerifiableCredential.Create.PresentRequest (Delegated)Issue and present Entra Verified ID credentials

Option C: Full Separation of Duties​

Create a separate app registration for each distinct Affirm operation. The following table lists the permissions for each operation.

OperationPermissions
Retrieve user profile dataUser.Read (Delegated), User.Read.All (Application)
Issue a Temporary Access PassDirectory.Read.All (Application), UserAuthenticationMethod.ReadWrite.All (Application)
Issue an Entra Verified ID credentialVerifiableCredential.Create.IssueRequest (Delegated)
Present an Entra Verified ID credentialVerifiableCredential.Create.PresentRequest (Delegated)