Trusona vs. Microsoft Entra Verified ID
A locked-out caller is on the line and your agent has to decide who they are. One approach needs the caller holding a credential in Microsoft Authenticator, issued either in advance or by a third-party identity verification provider. The other asks for a government ID and checks it against the authority that issued it.
Trusona and Microsoft Entra Verified ID both verify identity at the IT help desk. They ask different things of the caller. Entra Verified ID verifies a verifiable credential the user holds in a wallet, and for Face Check that wallet is Microsoft Authenticator. In Microsoft’s account recovery flow, which Microsoft documents as self-service and says “replaces manual helpdesk-led recovery,” the user first completes a government ID check with an identity verification partner your tenant has integrated from Microsoft’s gallery; then the identity verification provider issues the Verified ID credential, and the user presents it to Microsoft Entra ID. Face Check adds a real-time selfie, matched against the photo in that credential “in the cloud, using Azure AI Vision Face API.” Trusona asks the caller for one thing. Scan a government ID in the phone’s browser. Trusona verifies it against the authority that issued it, in the US the state DMV over the AAMVA network, and returns a result to the agent in real time. No app, no credential, no selfie, no PII stored.
One step, then a result
The caller needs a phone. Nothing to install, nothing registered in advance. They scan a government ID in the mobile browser and ATO Protect verifies it against the authority that issued it, in the US the state DMV over the AAMVA network. The agent gets a red, yellow or green risk summary while the caller is still on the line. It covers 2,500+ document types worldwide, detects SIM swaps and port-outs, carries patented man-in-the-middle and scan anti-replay detection, and stores no PII.
A credential, then a face match
The caller needs Microsoft Authenticator, because Face Check “is limited to Verified ID usage with Microsoft Authenticator.” For account recovery, your tenant needs an identity verification partner from Microsoft’s IDV gallery. In account recovery that partner runs the government ID check, then the identity verification provider issues the Verified ID credential, and the caller “presents their newly acquired Verified ID” to Microsoft Entra ID. Face Check captures a real-time selfie and matches it against the photo in the credential, in the cloud through Azure AI Vision. Microsoft offers this for help desk password resets and passkey activation.
What has to be in place before the check can run
Microsoft documents two patterns, and each carries a stack.
For the service desk pattern, Microsoft’s setup steps are: set up Verified ID in your tenant, “Issue Verified ID to your users,” and “Add verification flow to your existing service desk solution.” Face Check then matches a live selfie against the photo in the credential the caller already holds, and it runs only inside Microsoft Authenticator.
For account recovery, Microsoft documents a self-service flow that “replaces manual helpdesk-led recovery.” The user is redirected to an identity verification provider, the provider checks a government ID with liveness and facial recognition, the user receives a Verified ID credential in Microsoft Authenticator, presents it to Microsoft Entra ID, and receives a Temporary Access Pass.
Either way, the person being verified ends up holding a credential in Microsoft Authenticator, and your tenant stands up Verified ID or contracts an identity verification provider first.
Trusona’s list is one line long. A phone. The caller scans a government ID in the mobile browser and Trusona checks it against the authority that issued it.
| What the help desk is buying | Trusona ATO Protect | Microsoft Entra Verified ID |
|---|---|---|
| What the caller needs before the check can run | A phone. Nothing installed, nothing registered in advance. | Microsoft Authenticator to hold the Verified ID credential, plus either a credential your tenant issued in advance or an identity verification provider your tenant has contracted. |
| App download | None. The ID scan runs in the mobile browser. | Microsoft Authenticator. Microsoft states Face Check “is limited to Verified ID usage with Microsoft Authenticator.” |
| Third-party identity verification vendor | None. Trusona runs the check. | Required in Microsoft’s documented account recovery flow. Microsoft routes the government ID check to a partner from its IDV gallery. |
| Verifiable credential the caller must hold | None. | Required. In the service desk pattern Microsoft’s setup step is “Issue Verified ID to your users.” In account recovery the identity verification provider issues it during the recovery session. |
| Live selfie or liveness biometric | None. Trusona does not run a liveness check, because generative AI can now defeat those methods. | Required for Face Check, which performs “facial matching between a user’s real-time selfie and a photo.” |
| Where the biometric match happens | No biometric match. Trusona takes no selfie and stores no biometric. | Off the device. Microsoft states the check is “performed in the cloud, using Azure AI Vision Face API.” |
| Works with a first-time caller who has nothing installed | Yes. The caller opens a link and scans an ID. | Not in the service desk pattern, where Microsoft’s setup step is “Issue Verified ID to your users.” Account recovery does verify someone holding no credential, as a self-service flow: the user is redirected to an identity verification provider, receives a Verified ID credential in Microsoft Authenticator, and presents it to Microsoft Entra ID. |
| What the person being verified has to complete | One thing. Scan the ID. | Microsoft documents four stages for account recovery: account discovery, identity verification with the provider, credential validation, and access restoration with a Temporary Access Pass. |
| Checks the ID against the issuing authority’s record in real time1 | Yes. In the US, the state DMV over the AAMVA network. | Not published. Verifies a credential the user holds; the government ID check runs at issuance, through a Microsoft IDV partner. |
| Worldwide document coverage | 2,500+ document types. | Not published. Coverage depends on the IDV partner your tenant integrates. |
| SIM swap and port-out detection | Yes. | Not published. |
| Man-in-the-middle detection | Yes, patented (US Pat. 10,601,859). | Not published. |
| Scan anti-replay detection | Yes, patented (US Pat. 10,601,859). | Published, for the selfie. Microsoft states Face Check results “can’t be replayed or manipulated on compromised devices,” and that Azure Face API AI and Face Check “are iBeta Level 2 conformant.” Trusona’s anti-replay is patented and applies to the ID scan. |
| Reverse check, where the caller verifies the agent | Yes. ATO Protect – Agent Verify, patent pending. | Not published. |
| What the agent sees | A red, yellow or green result, not the caller’s identity documents. | A match confidence score. Microsoft states “the verifier application only receives a confidence score of the resulting match,” returned with the credential’s claims. Organizations set the threshold; the default is 70. |
| Personal data retained | None. Trusona stores no PII. SOC 2 infrastructure. | The credential and its photo sit in the user’s wallet. Microsoft states the selfie “is discarded and not saved on any device or service.” |
1 Microsoft describes account recovery as using government-issued identification and biometric verification through certified identity verification providers, and its IDV partner gallery states these scenarios “use Government ID checks through identity verification and proofing services.” Microsoft does not publish a check against the issuing authority’s record, in the US the state DMV over AAMVA. “Not published” means a capability Microsoft does not describe on its public Verified ID and account recovery documentation, not confirmation that it is absent. Sources: learn.microsoft.com/en-us/entra/identity/authentication/concept-account-recovery-overview and learn.microsoft.com/en-us/entra/verified-id/idv-partners, accessed August 13, 2026.
Questions buyers ask
What does the person being verified have to do?
Does Microsoft Entra Verified ID do help desk identity verification?
Does the caller need the Microsoft Authenticator app or a credential?
Does either one check the ID against the authority that issued it?
Does Trusona use facial recognition or selfies?
What does each one retain about the caller?
Comparison based on Microsoft’s own Entra Verified ID, Face Check, IDV partner and account recovery documentation on learn.microsoft.com, fetched July 2026 and re-checked August 13, 2026, against Trusona’s fact base for this comparison, corrected August 13, 2026. Quoted phrases are Microsoft’s. “Not published” means a capability Microsoft does not describe on its public Verified ID and account recovery documentation, not confirmation that it is absent. Trusona claims are from trusona.com. Page updated August 13, 2026.