Microsoft Entra

This document outlines the steps required to enable CLEAR for Account Recovery within Microsoft Entra. Users may use Account Recovery to re-gain access into their microsoft accounts

Overview

Use CLEAR within Microsoft Entra to create identity-backed, self-service account
recovery for any workforce population, including employees, contractors, partners,
and privileged users.

With CLEAR + Microsoft Entra Account Recovery, organizations can verify a user's
identity before granting a Temporary Access Pass (TAP), eliminating the need for a
help desk call, one-time passcode, or alternate workaround when someone is locked
out of their account.

By replacing traditional recovery paths — call center transfers, security
questions, and OTPs — with biometric identity verification, organizations can shut
down social engineering as an attack vector, reduce help desk case volume, and
return locked-out employees to work in seconds instead of minutes.

Whether supporting forgotten password recovery, MFA reset, new hire onboarding,
device re-provisioning, or high-assurance workforce use cases, CLEAR helps ensure
the person triggering account recovery is actually the employee on record — not an
attacker impersonating them.

What is Account Recovery

Account Recovery is a Microsoft process that allows employees(users) to re-gain access into their accounts by performing a set of actions to prove they are indeed who they say they are. Historcially, Account Recovery was a process that when triggered, required an employee to speak with a call center agent, use a one-time passcode, or alternate means to prove to a degree that the human attempting to recover is indeed who they say they are

CLEAR has partnered with Microsoft to:

Ensure Employee triggering Account Recovery = Employee Decrease help desk Account Recovery cases / Mitigate social engineering.

The Problem with Traditional Account Recovery

historcially, Account recovery is a major attack vector for social engineering. Bad actors would pose as employees locked out of accounts in an attempt to gain access to real employees account resulting in data breaches and major attacks

The Solution: CLEAR + Microsoft Account Recovery

CLEAR has partnered with Microsoft to: create Identity backed self service account recovery flows.

Demo:

Outcomes For Our Customers

This ensure the following

  1. The employee triggering Account Recovery is actuually the employee
  2. Decrease help desk Account Recovery cases
  3. Mitigate social engineering across companies by adding an multi-layered identity appraoch to account recovery

Outcomes For Employees

  1. Self Service: Employees get the benefit of re-gaining access their accounts without needing to call a help desk. Instead of a 5-10 min phone call, they can regain access in minutes to seconds.
  2. Network Effect: Unike traditional identity providers, CLEAR can help employees re-gain access with a quick snap of a selfie. Once an employee completes CLEAR one time by adding their phone number, adding a selfie, and document, their data is stored and can be leveraged later to unlock an account with just a selfie.

To read more about how CLEAR works check out our guide covering our end user experience:

How It Works

End User Experience

Employee Selects Recover Account → Verifies with CLEAR → Temporary Access Pass (TAP) Provided → Logs in

Behind the scenes: _CLEAR data is used to issue a Verified ID(VID), data from VID matched to MSFT Entra employee data, CLEAR selfie is matched with selfie in real-time, clear user ID (PSUID) is added to employee record


Admin Configuration Experience

Microsoft Entra Admins can setup CLEAR + Microsoft SSAR in minutes within Entra.

Entra global admins navigate to https://entra.microsoft.com/ → select account recovery → follow setup wizard and guide below.

Setup Overview

CLEAR has partnered with Microsoft to enable account recovery workflows using CLEAR. This guides walks through the process of enabling CLEAR for account recovery within Microsoft Entra

Pre-Requisites

To Configure within Entra

Admins must possess the folloing permissions

To Trigger As Employee(User)

  • End Users Microsoft Authenticator App Phone

Setting up Account Recovery+CLEAR within Microsoft Entra

Step 1 Get Started

Navigate to https://entra.microsoft.com/ select account recovery on the side bar


Step 2 Select Enviroment and Users

Select Get Started under setup account recovery and follow the guided steps

  1. Recovery Mode: Select Production and click next
  2. User Groups: define the user groups Account Recovery will be enabled or disabled. Admins can select which groups to include specifically or exclude.
    1. Include: Select specific groups and users that account recovery will be enabled for, when users click recover account they will complete the CLEAR+Account Recovery Workflow
    2. Exclude: Select specific groups and users that account recovery still be disabled for. When these users click recover my account in the sign-in flow, they will NOT use CLEAR+Microsoft Account Recovery


Step 3 Select Identity Provider

Select CLEAR as the identity provider and click the Microsoft Security Store button to enable CLEAR

⚠️

NOTE: you will need to revisit this setup wizard after CLEAR is enabled. Once enabled you will complete the account validation and review and finalize steps

Step 4 Get Solution (Activate CLEAR)

Select “get solution" and complete the workflow.

  1. Select Resource Group, this should match your Entra tenant group
  2. Add Resource name
  3. Select Plan: Consumption or Existing Customers
    1. New Customers If you are not a current customer please select consumption. This allows CLEAR to create a CLEAR tenant (organization), api key, and projectID for you and automatically enable CLEAR within Microsoft Entra.
    2. Existing Customers If you have an existing CLEAR subscription please select Existing Customers. This will allow you to add your own API key and projectID to power the Account Recovery workflow.
❗️

IMPORTANT -- Existing Customers Please navigate to the CLEAR console in a sepeate tab to retrieve your projectID from the projects tab, and api key from the integrations tab. These two values will be critical to power CLEAR within Microsoft Entra.

After you select plan, place order and move on CLEAR to add a few more details




Step 5 Activate CLEAR

Existing Customers

Please add your projectID and API key from the clear console to activate CLEAR and continue to next steps

New Customers

Please select your company size, agree to terms & conditions, and click Activate


Step 6 Complete Account Recovery Setup

Complete setup within https://entra.microsoft.com/

Navigate back to Entra > account recovery and complete the remaining setup steps.

📘

NOTE: You should have completed account validation up to this point.

To configure Account Validation, select match confidence (exact of relaxed)

Please connect with your team to decide the level of rigor placed on matching between CLEAR data and the Entra record. You have the choice to choose between exact match which means the data from CLEAR needs (first and last name) need to match the exact name on the employee record. Relax enables slight flexibility within the first and last name match_


Step 7 Review and finalize

After all of the steps are completed, configuration is complete! Click complete and Account Recovery with CLEAR is now enabled



Testing and Validation

To test, end employees(users) can add their email to begin the traditional login flow, after adding their email the user can select Recover Account and the Account Recovery with CLEAR process will begin





Complete! Account Recovery + CLEAR Enabled!



Did this page help you?