How to Fix Azure Publisher Domain Verification for GitHub-Hosted Files
Question details
The user needs to resolve an issue where Azure rejects the publisherDomain property during verification.

- Product
- Microsoft Azure / Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Verifying an application publisher domain in Azure using a Microsoft identity association file hosted via a GitHub raw URL.
- Observed behavior
- Azure rejects the publisherDomain property and fails the domain verification process, even though the identity association file is publicly accessible via the GitHub URL.
Ensure you have global administrator or application administrator privileges in your Microsoft Entra ID tenant, and verify that the domain you are trying to verify is already added to your custom domain names.
Verify Publisher Domain via App Registrations Branding
Check and configure the publisher domain settings directly in the Azure portal to ensure the custom domain is correctly associated with your tenant.
Often, using a direct GitHub raw URL (raw.githubusercontent.com) causes a mismatch with the actual custom domain you are trying to verify. Azure expects the microsoft-identity-association.json file to be hosted exactly on the domain being verified.
Sign in to the Azure portal and navigate to 'Microsoft Entra ID' (formerly Azure Active Directory).
From the left-hand menu, select 'App registrations' and click on the application you are trying to configure.
In the application menu, select 'Branding & properties' to view the publisher domain settings.
Locate the 'Publisher domain' section. Ensure your target domain is selected. If it is unverified, click 'Update domain' and complete the 'Verify and save domain' process.

Contact Support for Persistent Verification Failures
If the domain verification continues to fail despite correct configuration and file hosting, escalate the issue for investigation.
Manage Your Development and IT Documentation with WPS Office
While WPS Office cannot directly alter Microsoft Entra ID domain settings, it is the perfect lightweight and free alternative to Microsoft Office. Use it to effortlessly draft IT configurations, document troubleshooting steps, and create support requests without subscription fees.
- 1. Open WPS Writer: Launch WPS Office and open a new Writer document to start drafting your IT documentation.
- 2. Document Azure Settings: Copy and paste your JSON configurations, tenant details, and troubleshooting logs into the document.
- 3. Save and Share: Save your document in .docx format to easily share with your team or Microsoft Support.

Frequently Asked Questions
Why does Azure reject my GitHub raw URL for domain verification?
Azure requires the microsoft-identity-association.json file to be hosted at the exact '/.well-known/' path on the specific domain you are verifying. GitHub raw URLs use the raw.githubusercontent.com domain, which causes a domain mismatch during Microsoft Entra ID verification.
What is the purpose of the publisher domain in Azure?
The publisher domain is displayed to users on the application's consent prompt. It acts as a verified identity marker, helping users confirm they are granting permissions to a trusted and authentic application.
What does 'verify a new domain' mean in Azure App registrations?
Verifying a new domain involves proving ownership of that domain to Microsoft. This is typically done by placing a specific JSON file at the root of your web server or by adding TXT records to your DNS settings, enabling Azure to trust and link the domain to your tenant.
Do I need special permissions to verify a publisher domain?
Yes, you must be signed in with at least the Application Administrator or Global Administrator role in your Microsoft Entra ID tenant to successfully configure and verify publisher domains.




