Microsoft Entra
This document outlines the steps required to enable CLEAR for Account Recovery within Microsoft Entra. Users may use Account Recovery to re-gain access into their microsoft accounts
Overview
Use CLEAR within Microsoft Entra to create identity-backed, self-service account
recovery for any workforce population, including employees, contractors, partners,
and privileged users.
With CLEAR + Microsoft Entra Account Recovery, organizations can verify a user's
identity before granting a Temporary Access Pass (TAP), eliminating the need for a
help desk call, one-time passcode, or alternate workaround when someone is locked
out of their account.
By replacing traditional recovery paths — call center transfers, security
questions, and OTPs — with biometric identity verification, organizations can shut
down social engineering as an attack vector, reduce help desk case volume, and
return locked-out employees to work in seconds instead of minutes.
Whether supporting forgotten password recovery, MFA reset, new hire onboarding,
device re-provisioning, or high-assurance workforce use cases, CLEAR helps ensure
the person triggering account recovery is actually the employee on record — not an
attacker impersonating them.
What is Account Recovery
Account Recovery is a Microsoft process that allows employees(users) to re-gain access into their accounts by performing a set of actions to prove they are indeed who they say they are. Historcially, Account Recovery was a process that when triggered, required an employee to speak with a call center agent, use a one-time passcode, or alternate means to prove to a degree that the human attempting to recover is indeed who they say they are
CLEAR has partnered with Microsoft to:
Ensure Employee triggering Account Recovery = Employee Decrease help desk Account Recovery cases / Mitigate social engineering.
The Problem with Traditional Account Recovery
historcially, Account recovery is a major attack vector for social engineering. Bad actors would pose as employees locked out of accounts in an attempt to gain access to real employees account resulting in data breaches and major attacks
The Solution: CLEAR + Microsoft Account Recovery
CLEAR has partnered with Microsoft to: create Identity backed self service account recovery flows.
Demo:
Outcomes For Our Customers
This ensure the following
- The employee triggering Account Recovery is actuually the employee
- Decrease help desk Account Recovery cases
- Mitigate social engineering across companies by adding an multi-layered identity appraoch to account recovery
Outcomes For Employees
- Self Service: Employees get the benefit of re-gaining access their accounts without needing to call a help desk. Instead of a 5-10 min phone call, they can regain access in minutes to seconds.
- Network Effect: Unike traditional identity providers, CLEAR can help employees re-gain access with a quick snap of a selfie. Once an employee completes CLEAR one time by adding their phone number, adding a selfie, and document, their data is stored and can be leveraged later to unlock an account with just a selfie.
To read more about how CLEAR works check out our guide covering our end user experience:
How It Works
End User Experience

Employee Selects Recover Account → Verifies with CLEAR → Temporary Access Pass (TAP) Provided → Logs in
Behind the scenes: _CLEAR data is used to issue a Verified ID(VID), data from VID matched to MSFT Entra employee data, CLEAR selfie is matched with selfie in real-time, clear user ID (PSUID) is added to employee record
Admin Configuration Experience
Microsoft Entra Admins can setup CLEAR + Microsoft SSAR in minutes within Entra.
Entra global admins navigate to https://entra.microsoft.com/ → select account recovery → follow setup wizard and guide below.
Setup Overview
CLEAR has partnered with Microsoft to enable account recovery workflows using CLEAR. This guides walks through the process of enabling CLEAR for account recovery within Microsoft Entra
Pre-Requisites
To Configure within Entra
Admins must possess the folloing permissions
- Microsoft Entra "Admin"
- Permissions/Roles: Global Admin
- Logged user needs to have Owner/Contributor permission on Azure RBAC roles to purchase and subscribe to CLEAR1 offer.
- Details Microsoft entitlements and requirements here
To Trigger As Employee(User)
- End Users Microsoft Authenticator App Phone
Setting up Account Recovery+CLEAR within Microsoft Entra
Step 1 Get Started
Navigate to https://entra.microsoft.com/ select account recovery on the side bar

Step 2 Select Enviroment and Users
Select Get Started under setup account recovery and follow the guided steps
- Recovery Mode: Select Production and click next
- User Groups: define the user groups Account Recovery will be enabled or disabled. Admins can select which groups to include specifically or exclude.
- Include: Select specific groups and users that account recovery will be enabled for, when users click recover account they will complete the CLEAR+Account Recovery Workflow
- Exclude: Select specific groups and users that account recovery still be disabled for. When these users click recover my account in the sign-in flow, they will NOT use CLEAR+Microsoft Account Recovery


Step 3 Select Identity Provider
Select CLEAR as the identity provider and click the Microsoft Security Store button to enable CLEAR
NOTE: you will need to revisit this setup wizard after CLEAR is enabled. Once enabled you will complete the account validation and review and finalize steps

Step 4 Get Solution (Activate CLEAR)
Select “get solution" and complete the workflow.
- Select Resource Group, this should match your Entra tenant group
- Add Resource name
- Select Plan: Consumption or Existing Customers
- New Customers If you are not a current customer please select consumption. This allows CLEAR to create a CLEAR tenant (organization), api key, and projectID for you and automatically enable CLEAR within Microsoft Entra.
- Existing Customers If you have an existing CLEAR subscription please select Existing Customers. This will allow you to add your own API key and projectID to power the Account Recovery workflow.
IMPORTANT -- Existing Customers Please navigate to the CLEAR console in a sepeate tab to retrieve your projectID from the projects tab, and api key from the integrations tab. These two values will be critical to power CLEAR within Microsoft Entra.
After you select plan, place order and move on CLEAR to add a few more details




Step 5 Activate CLEAR
Existing Customers
Please add your projectID and API key from the clear console to activate CLEAR and continue to next steps

New Customers
Please select your company size, agree to terms & conditions, and click Activate

Step 6 Complete Account Recovery Setup
Complete setup within https://entra.microsoft.com/
Navigate back to Entra > account recovery and complete the remaining setup steps.
NOTE: You should have completed account validation up to this point.
To configure Account Validation, select match confidence (exact of relaxed)
Please connect with your team to decide the level of rigor placed on matching between CLEAR data and the Entra record. You have the choice to choose between exact match which means the data from CLEAR needs (first and last name) need to match the exact name on the employee record. Relax enables slight flexibility within the first and last name match_

Step 7 Review and finalize
After all of the steps are completed, configuration is complete! Click complete and Account Recovery with CLEAR is now enabled

Testing and Validation
To test, end employees(users) can add their email to begin the traditional login flow, after adding their email the user can select Recover Account and the Account Recovery with CLEAR process will begin



Complete! Account Recovery + CLEAR Enabled!
Updated 9 days ago