How to set up self-service account recovery with Entra ID
This tutorial will describe the steps to configure Nametag for self-service account recovery with Entra ID.
-
Sign in to Nametag at https://www.getnametag.com and select “Sign in”
-
Press Configure.
-
On the left side, choose Entra ID
-
Press Connect directory and follow the prompts to authorize Nametag to access your Entra ID.
Note: You must be a domain administrator in Entra ID to complete this step.
-
When complete, you will be redirected back to Nametag. Nametag will immediately start to synchronize user accounts from your Entra ID. This may take a few minutes.
Note: Nametag synchronizes user accounts from your Entra ID every hour, but if you would like to synchronize immediately, you can press Sync now.
-
Determine a URL for your account recovery website. This site should be hosted under a domain your users recognize, but will be hosted by Nametag. For example, if your company’s domain is
example.com, you might choosehttps://accounts.example.com. -
Update your DNS records to point your URL to Nametag using the
CNAMErecord type and target ofnametaghosted.com. For example:accounts.example.com. IN CNAME nametaghosted.com.Note: The target is exactly
nametaghosted.com. Do not point the record at your Nametag-hosted subdomain, such asexample.nametaghosted.com. -
In Nametag, select your environment and choose Self-service in the navigation. Enter your URL in the Self-service URL field, save it, then press Check again. Nametag checks the DNS record and issues a TLS certificate for your domain. Certificate issuance takes a minute or two, so press Check again until Nametag reports that both DNS and the certificate are configured correctly. No action is required from Nametag.
Note: You must have the Admin role in Nametag to change the self-service URL.
If your domain uses certificate pinning, or a
CAArecord on your domain prevents Nametag from issuing a certificate, add your own certificate and private key under Custom TLS Certificate on the same page. After you add a certificate, change yourCNAMErecord to targetalt.nametaghosted.com. Contact help@nametag.co if this applies to you. -
Direct your users to the new URL to verify their identities and recover their accounts in case of lockout.