When Microsoft introduced Entra Verified ID, it arrived with the language of the open identity movement: decentralized identifiers, credentials you hold in your own wallet, standards developed in the open. During the public preview, issuing credentials into the Microsoft Authenticator app cost nothing, and the biometric Face Check feature was free as well, right up until it went generally available on 12 August 2024.
That framing has quietly shifted. The technology still works, and parts of it are genuinely well built. But the commercial terms have moved from “free to adopt” toward “metered, and gated behind Microsoft licensing.” For any organization weighing Verified ID as the foundation of its digital identity, the important question is no longer “does it work,” but “what does it actually cost to run at scale, and whose ecosystem does it tie me to?”
What used to be free is now metered
Today, Microsoft Entra Verified ID gives you a free tier of up to 50,000 transactions per month, where a transaction is defined as the issuance, verification, or revocation of a credential. That sounds generous, until you realize that every credential a citizen or customer presents back to you counts against that pool. For a consumer-facing or public-sector service, 50,000 a month is not a high ceiling.
The moment you cross it, the terms change in a way that is easy to miss: to keep using Verified ID at all beyond the free tier, you must hold a Microsoft Entra ID P1 or P2 license. These are not one-off fees. They are per-user, per-month enterprise subscriptions (roughly $6 and $9 per user per month respectively). In other words, scaling your credential usage does not simply add a usage charge, it pulls your organization into Microsoft’s premium identity licensing across your user base.
On top of that sits Face Check, the biometric matching step that performs a facial comparison between a live selfie and the photo in a credential. Face Check is billed at €0.216 per verification in a pay-as-you-go model, or it is bundled as eight verifications per seat per month if you buy into the Microsoft Entra Suite, with anything beyond that charged at the same €0.216. Notably, Microsoft bills for a Face Check even when the match fails, as long as the request got past the QR scan.
A simple example makes the scale concrete. An organization that runs high-assurance identity checks on 100,000 people in a year pays €21,600 for the Face Check verifications alone, before any licensing, and if its monthly activity crosses the free tier, the relevant users must each carry a paid P1 or P2 license on top.
The lock-in is the licensing, not the line item
The subtle part is who pays and for what. In Verified ID, billing is attributed to the tenant that issues or verifies, not to the person holding the credential. The holder needs no Microsoft account and no license. That sounds clean, but it means the entire cost, and the entire dependency, sits with you, the operator. And the gate above the free tier is not a usage meter you can simply budget for, it is Microsoft Entra premium licensing, a product designed for managing your own workforce.
That is the heart of the lock-in. A general-purpose identity system serves people who are not your employees: citizens, customers, patients, students. Yet the only way to scale Verified ID is through licensing built around an enterprise workforce. If you are not already a committed Microsoft Entra customer, adopting Verified ID at scale effectively makes you one. Your identity infrastructure, your costs, and your roadmap become tied to a single vendor’s commercial decisions.
And those decisions change. Microsoft has more than once pushed breaking protocol updates that forced every credential in the Authenticator wallet to be reissued: the 2022 switch in how identifiers are generated, the migration from the old SDKs to the new Wallet Library, and the retirement of non-FIPS signing keys scheduled for 1 July 2026. Credentials your users hold today are durable only until the next platform change. That is a fragile foundation for something as long-lived as identity.
Not the road Europe is taking
There is a standards dimension here too. Europe’s eIDAS 2.0 regulation and its Architecture and Reference Framework set out a clear, mandatory technical path for the EU Digital Identity Wallet: the OpenID4VCI and OpenID4VP protocols in their finalized 1.0 form, with credentials in the SD-JWT VC and ISO mdoc formats, and trust anchored in published trusted lists.
Microsoft references the OpenID for Verifiable Credentials family in its documentation, so it would be wrong to say it ignores these standards outright. But the details diverge sharply from where Europe is heading. Verified ID issues credentials only in the older W3C Verifiable Credentials 1.1 JWT format, anchors trust in did:web, and points at an earlier draft of the issuance protocol rather than the finalized specification. It supports neither SD-JWT VC nor ISO mdoc, the two formats the EU makes mandatory for personal identification and qualified attestations. In practice, Microsoft Entra Verified ID is not compatible with the EU Digital Identity Wallet ecosystem. It is a parallel, vendor-specific profile, not the European one.
A different model: pay per verification, transparently
Let us be honest about Yivi: we are not free either. Yivi’s business model is built around paying per verification. The difference is not the existence of a price, it is how that price behaves.
With Yivi, you pay a single, published per-verification rate. There is no per-seat enterprise license you must buy across your user base to unlock the service, no separate biometric meter stacked on top, and no surprise threshold that flips you into a different commercial regime. The price is the price, and it does not change overnight or invalidate the credentials your users already hold.
Just as importantly, Yivi is built on the open standards Europe actually mandates, including OpenID4VP, OpenID4VCI, and SD-JWT VC, the same standards used worldwide for the EU Digital Identity Wallet. Your users hold their credentials in their own wallet, on their own device, and you are not tying your future to one company’s licensing roadmap. Open standards mean you can change providers; vendor lock-in means you cannot.
The question to ask before you commit
Microsoft Entra Verified ID is a capable product, and for an organization already deep in the Microsoft Entra ecosystem it may well fit. But “free during preview” was never the steady state, and it is worth seeing the full picture before you build on it: a metered free tier, a per-seat licensing gate above it, a per-verification charge for biometrics, periodic forced reissuance, and a standards profile that does not line up with the EU wallet.
For anyone building general-purpose, public-interest, or citizen-facing identity, the better questions are simple: whose standards is this built on, whose licensing am I tied to, and whose roadmap decides what happens next? Those are the questions Yivi was designed to answer differently.
Learn more or get started
- Understand what Yivi is: docs.yivi.app/what-is-yivi
- For developers: yivi.app/for_developers
- Download the Yivi app: available on iOS and Android
- Get in touch: questions about implementing Yivi? Contact us