Nametag Docs
Get help Launch Nametag
Docs Entra ID

How to set up self-service account recovery with Entra ID

This tutorial will describe the steps to configure Nametag for self-service account recovery with Entra ID.

  1. Sign in to Nametag at https://www.getnametag.com and select “Sign in”

  2. Press Configure.

  3. On the left side, choose Entra ID

  4. Press Connect directory and follow the prompts to authorize Nametag to access your Entra ID.

    Note: You must be a domain administrator in Entra ID to complete this step.

  5. When complete, you will be redirected back to Nametag. Nametag will immediately start to synchronize user accounts from your Entra ID. This may take a few minutes.

    Note: Nametag synchronizes user accounts from your Entra ID every hour, but if you would like to synchronize immediately, you can press Sync now.

  6. Determine a URL for your account recovery website. This site should be hosted under a domain your users recognize, but will be hosted by Nametag. For example, if your company’s domain is example.com, you might choose https://accounts.example.com.

  7. Update your DNS records to point your URL to Nametag using the CNAME record type and target of nametaghosted.com. For example:

    accounts.example.com. IN CNAME nametaghosted.com.
    

    Note: The target is exactly nametaghosted.com. Do not point the record at your Nametag-hosted subdomain, such as example.nametaghosted.com.

  8. In Nametag, select your environment and choose Self-service in the navigation. Enter your URL in the Self-service URL field, save it, then press Check again. Nametag checks the DNS record and issues a TLS certificate for your domain. Certificate issuance takes a minute or two, so press Check again until Nametag reports that both DNS and the certificate are configured correctly. No action is required from Nametag.

    Note: You must have the Admin role in Nametag to change the self-service URL.

    If your domain uses certificate pinning, or a CAA record on your domain prevents Nametag from issuing a certificate, add your own certificate and private key under Custom TLS Certificate on the same page. After you add a certificate, change your CNAME record to target alt.nametaghosted.com. Contact help@nametag.co if this applies to you.

  9. Direct your users to the new URL to verify their identities and recover their accounts in case of lockout.