logo
search
Others

How to Fix Azure Publisher Domain Verification for GitHub-Hosted Files

WPS EditorWPS Editor Sep 28, 2026 869 views

Question details

The user needs to resolve an issue where Azure rejects the publisherDomain property during verification.

How to Fix Azure Publisher Domain Verification for GitHub-Hosted Files
Product
Microsoft Azure / Microsoft Entra ID
Device & OS
not provided
Scenario
Verifying an application publisher domain in Azure using a Microsoft identity association file hosted via a GitHub raw URL.
Observed behavior
Azure rejects the publisherDomain property and fails the domain verification process, even though the identity association file is publicly accessible via the GitHub URL.
Before you start

Ensure you have global administrator or application administrator privileges in your Microsoft Entra ID tenant, and verify that the domain you are trying to verify is already added to your custom domain names.

Solution 1Recommended

Verify Publisher Domain via App Registrations Branding

Check and configure the publisher domain settings directly in the Azure portal to ensure the custom domain is correctly associated with your tenant.

Often, using a direct GitHub raw URL (raw.githubusercontent.com) causes a mismatch with the actual custom domain you are trying to verify. Azure expects the microsoft-identity-association.json file to be hosted exactly on the domain being verified.

1
Access Microsoft Entra ID

Sign in to the Azure portal and navigate to 'Microsoft Entra ID' (formerly Azure Active Directory).

2
Open App Registrations

From the left-hand menu, select 'App registrations' and click on the application you are trying to configure.

3
Navigate to Branding Settings

In the application menu, select 'Branding & properties' to view the publisher domain settings.

4
Verify the Domain

Locate the 'Publisher domain' section. Ensure your target domain is selected. If it is unverified, click 'Update domain' and complete the 'Verify and save domain' process.

Verify Publisher Domain via App Registrations Branding
Important Hosting Requirement: To successfully verify the domain, ensure the microsoft-identity-association.json file is hosted at https://yourdomain.com/.well-known/microsoft-identity-association.json rather than a GitHub raw URL.
Free Microsoft Office alternative

Manage Your Development and IT Documentation with WPS Office

While WPS Office cannot directly alter Microsoft Entra ID domain settings, it is the perfect lightweight and free alternative to Microsoft Office. Use it to effortlessly draft IT configurations, document troubleshooting steps, and create support requests without subscription fees.

  1. 1. Open WPS Writer: Launch WPS Office and open a new Writer document to start drafting your IT documentation.
  2. 2. Document Azure Settings: Copy and paste your JSON configurations, tenant details, and troubleshooting logs into the document.
  3. 3. Save and Share: Save your document in .docx format to easily share with your team or Microsoft Support.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight installation that runs smoothly alongside your heavy development environments.Excellent for formatting JSON scripts, drafting IT documentation, and managing project spreadsheets.Cross-platform support across Windows, Mac, Linux, iOS, and Android.
microsoft office alternative - wps office

Frequently Asked Questions

Why does Azure reject my GitHub raw URL for domain verification?

Azure requires the microsoft-identity-association.json file to be hosted at the exact '/.well-known/' path on the specific domain you are verifying. GitHub raw URLs use the raw.githubusercontent.com domain, which causes a domain mismatch during Microsoft Entra ID verification.

What is the purpose of the publisher domain in Azure?

The publisher domain is displayed to users on the application's consent prompt. It acts as a verified identity marker, helping users confirm they are granting permissions to a trusted and authentic application.

What does 'verify a new domain' mean in Azure App registrations?

Verifying a new domain involves proving ownership of that domain to Microsoft. This is typically done by placing a specific JSON file at the root of your web server or by adding TXT records to your DNS settings, enabling Azure to trust and link the domain to your tenant.

Do I need special permissions to verify a publisher domain?

Yes, you must be signed in with at least the Application Administrator or Global Administrator role in your Microsoft Entra ID tenant to successfully configure and verify publisher domains.