Skip to main content

Windows MDM setup issue with custom domain

What

When configuring FileWave'sFileWave Windows MDM integration with Microsoft Entra ID, and the Microsoft On-premises MDM application ismay addedfail towhen the Microsoft Entra tenant, attempting toyou add the URL of the FileWave server toURL thein Expose an API bladeas resultsthe inApplication anID error message stating:URI.

"Error: Failed to update Application ID URI application property. Error detail: The Application ID URI must be from a verified domain within your organization’s directory."

When/Why

MicrosoftThis institutedusually happens when the FileWave server URL uses a breakinghostname changethat is not under a domain verified in the customer’s Microsoft Entra ontenant, 10/15/such as a FileWave-owned hosted hostname.

Why this happens

Microsoft changed Application ID URI validation for single-tenant applications effective October 15, 2021. When a new Application ID URI is added, or an existing one is updated, Microsoft Entra validates that the host name in an HTTPS URI belongs to requirethe tenant’s initial onmicrosoft.com domain or to a verified custom domain in that tenant.

The general Microsoft rule also allows supported api:// Application ID URI formats. That exception does not solve this FileWave Windows MDM case because the use of verified domains in all apps. See https://docs.microsoft.com/en-us/azure/active-directory/develop/reference-breaking-changes#appid-uri-in-single-tenant-applications-will-require-use-of-default-scheme-or-verified-domains for more information.

This change impacts customers using theMicrosoft On-premises MDM app fromsetup Microsoft in that the configuration of that app requires the URL ofexpects the FileWave server URL to be addedused to the Expose an API blade of the app. Previously, a FileWave SaaS environment, such as filewave.net could be added toin the configuration.

With

Configurations created before Microsoft enforced this change, it is not possible to add an unverified domain.

Customer environments using the On-premises MDM app from Microsoft who had Microsoft Entra configured prior to the breaking changerule can continue to use that configurationwork as long as theythe doexisting Application ID URI is not attemptchanged. New configurations, or edits to change the URI on an existing app, are validated against the Exposecurrent anrule.

API

What blade.this means Anyfor FileWave Windows MDM

    Customer-owned domain: If the FileWave server is available at a hostname under a domain the customer controls, such as filewave.example.org, verify that domain in Microsoft Entra and use that hostname for the Windows MDM configuration. FileWave-hosted server on a FileWave-owned hostname: A hostname such as a filewave.net address is owned by FileWave, not by the customer’s Microsoft Entra tenant. The customer cannot verify FileWave’s domain in their tenant, so that hostname cannot be used as the Application ID URI for a new customerWindows environmentsMDM attemptingsetup. Grandfathered setup: If Windows MDM was configured before the October 2021 Microsoft change and is still working, avoid changing the Application ID URI until you are ready to usemove the FileWave server URL to a verified customer-owned domain.

    How to fix it

      Choose a FileWave server hostname under a domain the customer owns or can verify in Microsoft Entra, for example filewave.example.org. Add and verify the domain in Microsoft Entra: Add your custom domain name to your tenant. If the server is FileWave-hosted, work with FileWave Support to configure the hosted server for the customer-owned custom hostname and SSL certificate handling. See SSL Certificate Management for Custom Domains (FileWave-Hosted Servers). Use the verified custom-domain hostname when configuring the Microsoft On-premises MDM appapplication will not be able to use that app to integrate afor FileWave SaaSWindows tenantMDM. thatAfter has a filewave.net domain name withthe Microsoft Entra ID.app

      How

      configuration

      Foris customerssaved, whocontinue havewith the FileWave Windows MDM setup and verify enrollment with a FileWavetest environmentuser/device thatbefore rolling it out broadly.

      Important: The DNS and SSL work for a FileWave-hosted custom hostname is usingseparate afrom Microsoft Entra domain nameverification. of your own, youFileWave can continuehelp toroute useand secure the On-premiseshosted MDMserver app,hostname, but youthe needcustomer still needs to verify ownershiptheir of yourown domain throughin Microsoft.Microsoft Entra Theso processMicrosoft foraccepts verifyingthe ownershipApplication ofID aURI.

        Microsoft identity platform breaking change: Application ID URI verified-domain requirement Microsoft Entra app manifest: identifierUris attribute Add your custom domain is documented at:

         

        Customers who are on a FileWave SaaS tenant that currently uses a filewave.net domain name, and did not setup Windows MDM prior to 10/15/2021 would need to migrate to a server that uses a domain name that you can control so that it can be added to your Microsoft Entra tenant.

        tenant
        Pre-Requisites of Windows MDM Setup SSL Certificate Management for Custom Domains (FileWave-Hosted Servers)