Compare

Trusona vs. Microsoft Entra Verified ID

A locked-out caller is on the line and your agent has to decide who they are. One approach needs the caller holding a credential in Microsoft Authenticator, issued either in advance or by a third-party identity verification provider. The other asks for a government ID and checks it against the authority that issued it.

Trusona and Microsoft Entra Verified ID both verify identity at the IT help desk. They ask different things of the caller. Entra Verified ID verifies a verifiable credential the user holds in a wallet, and for Face Check that wallet is Microsoft Authenticator. In Microsoft’s account recovery flow, which Microsoft documents as self-service and says “replaces manual helpdesk-led recovery,” the user first completes a government ID check with an identity verification partner your tenant has integrated from Microsoft’s gallery; then the identity verification provider issues the Verified ID credential, and the user presents it to Microsoft Entra ID. Face Check adds a real-time selfie, matched against the photo in that credential “in the cloud, using Azure AI Vision Face API.” Trusona asks the caller for one thing. Scan a government ID in the phone’s browser. Trusona verifies it against the authority that issued it, in the US the state DMV over the AAMVA network, and returns a result to the agent in real time. No app, no credential, no selfie, no PII stored.

Trusona ATO Protect

One step, then a result

The caller needs a phone. Nothing to install, nothing registered in advance. They scan a government ID in the mobile browser and ATO Protect verifies it against the authority that issued it, in the US the state DMV over the AAMVA network. The agent gets a red, yellow or green risk summary while the caller is still on the line. It covers 2,500+ document types worldwide, detects SIM swaps and port-outs, carries patented man-in-the-middle and scan anti-replay detection, and stores no PII.

Microsoft Entra Verified ID

A credential, then a face match

The caller needs Microsoft Authenticator, because Face Check “is limited to Verified ID usage with Microsoft Authenticator.” For account recovery, your tenant needs an identity verification partner from Microsoft’s IDV gallery. In account recovery that partner runs the government ID check, then the identity verification provider issues the Verified ID credential, and the caller “presents their newly acquired Verified ID” to Microsoft Entra ID. Face Check captures a real-time selfie and matches it against the photo in the credential, in the cloud through Azure AI Vision. Microsoft offers this for help desk password resets and passkey activation.

What has to be in place before the check can run

Microsoft documents two patterns, and each carries a stack.

For the service desk pattern, Microsoft’s setup steps are: set up Verified ID in your tenant, “Issue Verified ID to your users,” and “Add verification flow to your existing service desk solution.” Face Check then matches a live selfie against the photo in the credential the caller already holds, and it runs only inside Microsoft Authenticator.

For account recovery, Microsoft documents a self-service flow that “replaces manual helpdesk-led recovery.” The user is redirected to an identity verification provider, the provider checks a government ID with liveness and facial recognition, the user receives a Verified ID credential in Microsoft Authenticator, presents it to Microsoft Entra ID, and receives a Temporary Access Pass.

Either way, the person being verified ends up holding a credential in Microsoft Authenticator, and your tenant stands up Verified ID or contracts an identity verification provider first.

Trusona’s list is one line long. A phone. The caller scans a government ID in the mobile browser and Trusona checks it against the authority that issued it.

Side by side
What the help desk is buying Trusona ATO Protect Microsoft Entra Verified ID
What the caller needs before the check can run A phone. Nothing installed, nothing registered in advance. Microsoft Authenticator to hold the Verified ID credential, plus either a credential your tenant issued in advance or an identity verification provider your tenant has contracted.
App download None. The ID scan runs in the mobile browser. Microsoft Authenticator. Microsoft states Face Check “is limited to Verified ID usage with Microsoft Authenticator.”
Third-party identity verification vendor None. Trusona runs the check. Required in Microsoft’s documented account recovery flow. Microsoft routes the government ID check to a partner from its IDV gallery.
Verifiable credential the caller must hold None. Required. In the service desk pattern Microsoft’s setup step is “Issue Verified ID to your users.” In account recovery the identity verification provider issues it during the recovery session.
Live selfie or liveness biometric None. Trusona does not run a liveness check, because generative AI can now defeat those methods. Required for Face Check, which performs “facial matching between a user’s real-time selfie and a photo.”
Where the biometric match happens No biometric match. Trusona takes no selfie and stores no biometric. Off the device. Microsoft states the check is “performed in the cloud, using Azure AI Vision Face API.”
Works with a first-time caller who has nothing installed Yes. The caller opens a link and scans an ID. Not in the service desk pattern, where Microsoft’s setup step is “Issue Verified ID to your users.” Account recovery does verify someone holding no credential, as a self-service flow: the user is redirected to an identity verification provider, receives a Verified ID credential in Microsoft Authenticator, and presents it to Microsoft Entra ID.
What the person being verified has to complete One thing. Scan the ID. Microsoft documents four stages for account recovery: account discovery, identity verification with the provider, credential validation, and access restoration with a Temporary Access Pass.
Checks the ID against the issuing authority’s record in real time1 Yes. In the US, the state DMV over the AAMVA network. Not published. Verifies a credential the user holds; the government ID check runs at issuance, through a Microsoft IDV partner.
Worldwide document coverage 2,500+ document types. Not published. Coverage depends on the IDV partner your tenant integrates.
SIM swap and port-out detection Yes. Not published.
Man-in-the-middle detection Yes, patented (US Pat. 10,601,859). Not published.
Scan anti-replay detection Yes, patented (US Pat. 10,601,859). Published, for the selfie. Microsoft states Face Check results “can’t be replayed or manipulated on compromised devices,” and that Azure Face API AI and Face Check “are iBeta Level 2 conformant.” Trusona’s anti-replay is patented and applies to the ID scan.
Reverse check, where the caller verifies the agent Yes. ATO Protect – Agent Verify, patent pending. Not published.
What the agent sees A red, yellow or green result, not the caller’s identity documents. A match confidence score. Microsoft states “the verifier application only receives a confidence score of the resulting match,” returned with the credential’s claims. Organizations set the threshold; the default is 70.
Personal data retained None. Trusona stores no PII. SOC 2 infrastructure. The credential and its photo sit in the user’s wallet. Microsoft states the selfie “is discarded and not saved on any device or service.”

1 Microsoft describes account recovery as using government-issued identification and biometric verification through certified identity verification providers, and its IDV partner gallery states these scenarios “use Government ID checks through identity verification and proofing services.” Microsoft does not publish a check against the issuing authority’s record, in the US the state DMV over AAMVA. “Not published” means a capability Microsoft does not describe on its public Verified ID and account recovery documentation, not confirmation that it is absent. Sources: learn.microsoft.com/en-us/entra/identity/authentication/concept-account-recovery-overview and learn.microsoft.com/en-us/entra/verified-id/idv-partners, accessed August 13, 2026.

Questions buyers ask

What does the person being verified have to do?
With Trusona, one thing. Scan a government ID in the phone’s browser, while the caller is still on the line with your agent. Entra Verified ID depends on the person holding a Verified ID credential in Microsoft Authenticator. In the service desk pattern Microsoft’s setup step is “Issue Verified ID to your users,” so the credential is in place before the call. In account recovery the identity verification provider issues it during the session, but Microsoft documents that flow as self-service: it “replaces manual helpdesk-led recovery,” and your agent is not part of it. Either way the dependency is the same. Something has to be in the caller’s wallet before the check can run.
Does Microsoft Entra Verified ID do help desk identity verification?
It does, once the prerequisites are in place. Microsoft offers Face Check for help desk scenarios including password reset and passkey activation, and separately documents an account recovery flow that “replaces manual helpdesk-led recovery” with self-service identity proofing. The help desk pattern needs Verified ID set up in your tenant, credentials issued to your users, Microsoft Authenticator on their devices, and a selfie matched in the cloud. Trusona asks the caller to scan a government ID and verifies it against the authority that issued it. Many teams already run Microsoft Entra ID, and the ATOP API can connect to it.
Does the caller need the Microsoft Authenticator app or a credential?
For Entra Verified ID, both. Microsoft states Face Check “is limited to Verified ID usage with Microsoft Authenticator,” and Face Check matches against a credential held in that app. In account recovery the identity verification provider issues that credential during the recovery session, after completing the government ID check. Microsoft’s gallery lists established vendors, so this is a comparison of dependencies rather than of partners. Your caller and your tenant both have to put something in place before verification can begin. Trusona needs a phone.
Does either one check the ID against the authority that issued it?
Trusona does. It checks the government ID against the authority that issued it in real time, in the US the state DMV over the AAMVA network, across 2,500+ document types worldwide. Microsoft does not publish a check against the issuing authority’s record. Its documentation describes the government ID check running at issuance, through an identity verification partner. “Not published” means Microsoft does not describe the capability on its public Verified ID and account recovery documentation, not that it is absent.
Does Trusona use facial recognition or selfies?
No, by design. Trusona verifies a government ID against the authority that issued it. It runs no selfie or liveness check, because generative AI can now defeat those methods. Entra Verified ID’s Face Check takes the other route and requires a real-time selfie, matched in the cloud through Azure AI Vision.
What does each one retain about the caller?
Trusona retains no PII from a verification session and runs on SOC 2 infrastructure. The agent sees a risk result, not the caller’s identity documents. With Entra Verified ID, the credential and its photo sit in the user’s wallet in Microsoft Authenticator, and Microsoft states the selfie “is discarded and not saved on any device or service.”

Comparison based on Microsoft’s own Entra Verified ID, Face Check, IDV partner and account recovery documentation on learn.microsoft.com, fetched July 2026 and re-checked August 13, 2026, against Trusona’s fact base for this comparison, corrected August 13, 2026. Quoted phrases are Microsoft’s. “Not published” means a capability Microsoft does not describe on its public Verified ID and account recovery documentation, not confirmation that it is absent. Trusona claims are from trusona.com. Page updated August 13, 2026.