Windows MDM setup issue with custom domain
What
When configuring FileWave'sFileWave Windows MDM integration with Microsoft Entra ID, and the Microsoft On-premises MDM application ismay addedfail towhen the Microsoft Entra tenant, attempting toyou add the URL of the FileWave server toURL thein Expose an API bladeas resultsthe inApplication anID error message stating:URI.
"Error: Failed to update Application ID URI application property. Error detail: The Application ID URI must be from a verified domain within your organization’s directory."
When/Why
MicrosoftThis institutedusually happens when the FileWave server URL uses a breakinghostname changethat is not under a domain verified in the customer’s Microsoft Entra ontenant, 10/15/such as a FileWave-owned hosted hostname.
Why this happens
Microsoft changed Application ID URI validation for single-tenant applications effective October 15, 2021. When a new Application ID URI is added, or an existing one is updated, Microsoft Entra validates that the host name in an HTTPS URI belongs to requirethe tenant’s initial onmicrosoft.com domain or to a verified custom domain in that tenant.
The general Microsoft rule also allows supported api:// Application ID URI formats. That exception does not solve this FileWave Windows MDM case because the use of verified domains in all apps. See https://docs.microsoft.com/en-us/azure/active-directory/develop/reference-breaking-changes#appid-uri-in-single-tenant-applications-will-require-use-of-default-scheme-or-verified-domains for more information.
This change impacts customers using theMicrosoft On-premises MDM app fromsetup Microsoft in that the configuration of that app requires the URL ofexpects the FileWave server URL to be addedused to the Expose an API blade of the app. Previously, a FileWave SaaS environment, such as filewave.net could be added toin the configuration.
Configurations created before Microsoft enforced this change, it is not possible to add an unverified domain.
Customer environments using the On-premises MDM app from Microsoft who had Microsoft Entra configured prior to the breaking changerule can continue to use that configurationwork as long as theythe doexisting Application ID URI is not attemptchanged. New configurations, or edits to change the URI on an existing app, are validated against the Exposecurrent anrule.
What blade.this means Anyfor FileWave Windows MDM
filewave.example.org, verify that domain in Microsoft Entra and use that hostname for the Windows MDM configuration.
FileWave-hosted server on a FileWave-owned hostname: A hostname such as a filewave.net address is owned by FileWave, not by the customer’s Microsoft Entra tenant. The customer cannot verify FileWave’s domain in their tenant, so that hostname cannot be used as the Application ID URI for a new How to fix it
filewave.example.org.
Add and verify the domain in Microsoft Entra: Add your custom domain name to your tenant.
If the server is FileWave-hosted, work with FileWave Support to configure the hosted server for the customer-owned custom hostname and SSL certificate handling. See SSL Certificate Management for Custom Domains (FileWave-Hosted Servers).
Use the verified custom-domain hostname when configuring the Microsoft On-premises MDM How
configuration Foris customerssaved, whocontinue havewith the FileWave Windows MDM setup and verify enrollment with a FileWavetest environmentuser/device thatbefore rolling it out broadly.
Important: The DNS and SSL work for a FileWave-hosted custom hostname is
usingseparateafrom Microsoft Entra domainnameverification.of your own, youFileWave cancontinuehelptorouteuseand secure theOn-premiseshostedMDMserverapp,hostname, butyoutheneedcustomer still needs to verifyownershiptheirof yourown domainthroughinMicrosoft.Microsoft EntraThesoprocessMicrosoftforacceptsverifyingtheownershipApplicationofIDaURI.
Related documentation
Customers who are on a FileWave SaaS tenant that currently uses a filewave.net domain name, and did not setup Windows MDM prior to 10/15/2021 would need to migrate to a server that uses a domain name that you can control so that it can be added to your Microsoft Entra tenant.